Description
There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
Published: 2026-09-10
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Host OS Files
Action: Apply Patch
AI Analysis

Impact

An improper access control flaw in NI SystemLink allows an authenticated user with limited privileges to read host operating system files and directories that should be hidden. The vulnerability is rated high severity with a CVSS score of 8.6, indicating that successful exploitation could lead to confidentiality compromise of system data.

Affected Systems

The flaw affects NI SystemLink 2026 Q3 and earlier, and NI SystemLink Server 2026 Q3 and earlier. Systems running these products should verify that they are on the affected releases.

Risk and Exploitability

The vulnerability requires valid credentials for a user with limited privileges, suggesting that the attack surface is internal or requires credential compromise. Because the EPSS score is unavailable and the overall exploitation probability remains uncertain, but the high CVSS score and the ability to access host files elevate the risk. Adopting standard best practices such as monitoring for anomalous file access and enforcing the principle of least privilege can reduce the likelihood of successful exploitation.

Generated by OpenCVE AI on September 10, 2026 at 17:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch for NI SystemLink and NI SystemLink Server 2026 Q3 and earlier releases.
  • Restrict the privileges of all user accounts SystemLink environment.
  • Configure SystemLink to deny direct file system access to the host OS and audit file access logs for suspicious activity.

Generated by OpenCVE AI on September 10, 2026 at 17:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
Title Improper Access Controls in NI SystemLink
First Time appeared Ni
Ni systemlink
Ni systemlink Server
Weaknesses CWE-862
CPEs cpe:2.3:a:ni:systemlink:*:*:*:*:*:*:*:*
cpe:2.3:a:ni:systemlink_server:*:*:*:*:*:*:*:*
Vendors & Products Ni
Ni systemlink
Ni systemlink Server
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ni Systemlink Systemlink Server
cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2026-09-10T16:45:21.826Z

Reserved: 2026-03-13T14:11:47.565Z

Link: CVE-2026-4129

cve-icon Vulnrichment

Updated: 2026-09-10T16:45:13.823Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T16:17:14.080

Modified: 2026-09-10T19:55:45.477

Link: CVE-2026-4129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:45:06Z

Weaknesses