CVE-2026-9142: Insecure Default Credentials vulnerability in NI grpc-device when TLS configuration is not present
Published Jun 19, 2026
·Updated
There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback. This may allow an unauthenticated user access to the server on the local network. This affects NI grpc-device 2.17.0 and prior versions.
Affected Software
5 affected components
NI grpc-device<=2.17.0
NI InstrumentStudio<=2025
NI InstrumentStudio=2026-q1
NI InstrumentStudio=2026-q2
NI Ni Grpc Device Server<2.18.0
Event History
Jun 19, 2026
CVE Published
via MITRE·01:41 PM
Data Sourced
via MITRE·01:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Jul 3, 58550
Event
via FIRST·03:05 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-9142?
The severity of CVE-2026-9142 is rated critical with a score of 9.1.
2
Who is affected by CVE-2026-9142?
CVE-2026-9142 affects NI grpc-device version 2.17.0 and prior versions.
3
How do I fix CVE-2026-9142?
To fix CVE-2026-9142, ensure that TLS configuration is present and restrict the server binding to loopback only.
4
What kind of vulnerability is CVE-2026-9142?
CVE-2026-9142 is an insecure default credentials vulnerability.
5
What are the risks associated with CVE-2026-9142?
The risks associated with CVE-2026-9142 include unauthorized access to the server by unauthenticated users on the local network.