CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-9142

Critical · CVSS 9.1

NI grpc-device — Missing Authentication / Insecure Default Credentials (CWE-306)

CVSS
9.1
nvd
EPSS
0.31%
22th pct
KEV
No
Class
other
CWE-306

Description

There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback.  This may allow an unauthenticated user access to the server on the local network.  This affects NI grpc-device 2.17.0 and prior versions.

Search profile — drives PoC discovery

Symbols grpc-deviceTLS configurationloopbackinsecure default credentialsGHSA-fhhw-37q8-6562grpc_device_serverserver bindingunauthenticated access
Keywords CVE-2026-9142NI grpc-deviceinsecure default credentialsmissing authenticationCWE-306grpc-device TLS bypassunauthenticated grpc-deviceGHSA-fhhw-37q8-6562NI grpc-device PoCgrpc-device local network access
Versions: <= 2.17.0

References

Status: enriched · ingested 2026-06-25T18:00:38.000Z · profiled 2026-07-02T00:30:43.000Z