Description
There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3.
Published: 2026-09-10
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Host OS Files
Action: Apply Patch
AI Analysis

Impact

An improper access control vulnerability in NI SystemLink may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. The vulnerability is rated high severity with a CVSS score of 8.6, indicating that successful exploitation could lead to confidentiality compromise of system data.

Affected Systems

The flaw affects NI SystemLink and NI SystemLink Server versions predating the 2026 Q3 release. Systems running any of the affected releases should verify their version and apply remediation if needed.

Risk and Exploitability

The vulnerability requires valid credentials for a user with privileges, suggesting that the attack surface is internal or requires credential compromise. The EPSS score of 0.00201 (less than 1%) indicates a very low but non‑zero exploitation probability, while the CVSS score of 8.6 denotes a high potential impact. The vulnerability is not listed in the CISA KEV catalog. Adopting standard best practices such as monitoring for anomalous file access and enforcing the principle of least privilege can reduce the likelihood of successful exploitation.

Generated by OpenCVE AI on September 21, 2026 at 05:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch for NI SystemLink and NI SystemLink Server 2026 Q3 and earlier releases.
  • Restrict the privileges of all user accounts in the SystemLink environment.
  • Configure SystemLink to deny direct file system access to the host OS and audit file access logs for suspicious activity.

Generated by OpenCVE AI on September 21, 2026 at 05:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions. There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3.

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
Title Improper Access Controls in NI SystemLink
First Time appeared Ni
Ni systemlink
Ni systemlink Server
Weaknesses CWE-862
CPEs cpe:2.3:a:ni:systemlink:*:*:*:*:*:*:*:*
cpe:2.3:a:ni:systemlink_server:*:*:*:*:*:*:*:*
Vendors & Products Ni
Ni systemlink
Ni systemlink Server
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ni Systemlink Systemlink Server
cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2026-09-16T16:24:11.636Z

Reserved: 2026-03-13T14:11:47.565Z

Link: CVE-2026-4129

cve-icon Vulnrichment

Updated: 2026-09-10T16:45:13.823Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T16:17:14.080

Modified: 2026-09-16T17:17:19.210

Link: CVE-2026-4129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:30:07Z

Weaknesses