Listen to this Post
The `@grpc/grpc-js` library, a pure JavaScript implementation of gRPC’s core functionality, contains a critical improper authentication vulnerability identified as CVE-2026-101916. This flaw resides in the `getAuthContext` method, which is responsible for retrieving authentication context information from established connections. When server credentials are configured with the `requireClientCertificate` option set to false, the `getAuthContext` function fails to properly distinguish between authorized and unauthorized peer certificates in its return value.
The vulnerability arises from a logic error in the authentication context retrieval mechanism. Even when client certificate verification is not mandatory (requireClientCertificate: false), the server still allows connections without a client certificate. However, if a client presents a certificate that fails verification due to being untrusted or expired, the library incorrectly processes this state as an authorized connection. This results in the `getAuthContext` method returning authentication context data that indicates successful authorization for peers whose certificates were actually unauthorized.
This improper authentication vulnerability is particularly severe for applications that rely on the result of `getAuthContext` for making access control decisions, such as Role-Based Access Control (RBAC) systems. In particular, `@grpc/grpc-js-xds` can both set the `requireClientCertificate` option to `false` and use the return value of `getAuthContext` for RBAC authentication in some configurations, making it directly susceptible.
An attacker can exploit this vulnerability by presenting a self-signed, expired, or otherwise invalid certificate during the TLS handshake. Because the server accepts the connection due to `requireClientCertificate` being false, and subsequently misinterprets the failed validation as success via getAuthContext, the application layer will grant access based on flawed authentication data. This allows unauthorized entities to bypass security controls designed to restrict access to specific roles or identities.
The issue aligns with CWE-287 (Improper Authentication) and has been rated as High severity with a CVSS score of 7.4. The vulnerability affects `@grpc/grpc-js` versions prior to 1.13.6 and 1.14.5. It was published on September 17, 2026, by the National Vulnerability Database. The fix is available in versions 1.13.6 and 1.14.5.
DailyCVE Form:
Platform: gRPC
Version: Prior 1.13.6
Vulnerability: Improper Authentication
Severity: High
date: 2026-09-17
Prediction: 2026-09-28
What Undercode Say:
Check affected version
npm list @grpc/grpc-js
Vulnerable server configuration
const server = new grpc.Server();
server.bindAsync('0.0.0.0:50051', grpc.ServerCredentials.createSsl(
null, null, false // requireClientCertificate = false
), () => { server.start(); });
Exploit: present invalid client certificate
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 1
Use cert.pem (self-signed) in TLS handshake
Exploit: (Educational Purposes!)
An attacker can connect to a vulnerable gRPC server using a self-signed or expired certificate. Since `requireClientCertificate` is false, the server accepts the TLS connection. The attacker then calls an RPC method that relies on `getAuthContext` for authorization checks. Because `getAuthContext` returns the unauthorized certificate as though it were authorized, the attacker’s request is granted access to resources or operations that should be restricted.
Protection: from this CVE
- Upgrade `@grpc/grpc-js` to version 1.13.6 or 1.14.5.
- For `@grpc/grpc-js` users: set `requireClientCertificate` to `true` in server credentials.
- For `@grpc/grpc-js-xds` users using RBAC: set the `require_client_certificate` field to `true` in the `DownstreamTlsContext` in the xDS configuration.
- Avoid using `getAuthContext` for authorization decisions if possible.
Impact:
Successful exploitation allows unauthenticated remote clients to bypass access control mechanisms. Attackers can gain unauthorized access to gRPC services, potentially leading to data disclosure, privilege escalation, or other malicious actions depending on the application’s functionality. The vulnerability facilitates Initial Access techniques such as T1078 (Valid Accounts) if an attacker can spoof or manipulate certificate identities that are subsequently accepted by the application logic.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

