CVE-2026-48137: Untrusted pointer dereference in NI grpc-device sideband streaming API
There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution. Successful exploitation requires an attacker to supply a specially crafted Moniker protobuf message. This affects NI grpc-device 2.17.0 and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48137?
The severity of CVE-2026-48137 is rated as critical with a score of 9.3.
How do I fix CVE-2026-48137?
To fix CVE-2026-48137, update to the latest version of the National Instruments NI grpc-device software.
What type of vulnerability is CVE-2026-48137?
CVE-2026-48137 is an untrusted pointer dereference vulnerability.
What could happen if CVE-2026-48137 is exploited?
Exploitation of CVE-2026-48137 may lead to arbitrary memory dereference, potentially allowing for remote code execution.
What software is affected by CVE-2026-48137?
CVE-2026-48137 affects the National Instruments NI grpc-device software.