CVE-2026-48139: Ni Instrumentstudio

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attacker to cause a denial of service by triggering a crash.  Successful exploitation requires an attacker to provide an unknown value to the data moniker service. This affects NI grpc-device 2.17.0 and prior versions.

Affected products

  • Ni Instrumentstudio: up to and including 2025; version 2026 only
  • Ni Ni Grpc Device Server: before 2.18.0 (fixed in 2.18.0)

Published 2026-06-19. Last modified 2026-06-25.