Impact
An improper access control vulnerability in NI SystemLink may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. The vulnerability is rated high severity with a CVSS score of 8.6, indicating that successful exploitation could lead to confidentiality compromise of system data.
Affected Systems
The flaw affects NI SystemLink and NI SystemLink Server versions predating the 2026 Q3 release. Systems running any of the affected releases should verify their version and apply remediation if needed.
Risk and Exploitability
The vulnerability requires valid credentials for a user with privileges, suggesting that the attack surface is internal or requires credential compromise. The EPSS score of 0.00201 (less than 1%) indicates a very low but non‑zero exploitation probability, while the CVSS score of 8.6 denotes a high potential impact. The vulnerability is not listed in the CISA KEV catalog. Adopting standard best practices such as monitoring for anomalous file access and enforcing the principle of least privilege can reduce the likelihood of successful exploitation.
OpenCVE Enrichment