Impact
An improper access control flaw in NI SystemLink allows an authenticated user with limited privileges to read host operating system files and directories that should be hidden. The vulnerability is rated high severity with a CVSS score of 8.6, indicating that successful exploitation could lead to confidentiality compromise of system data.
Affected Systems
The flaw affects NI SystemLink 2026 Q3 and earlier, and NI SystemLink Server 2026 Q3 and earlier. Systems running these products should verify that they are on the affected releases.
Risk and Exploitability
The vulnerability requires valid credentials for a user with limited privileges, suggesting that the attack surface is internal or requires credential compromise. Because the EPSS score is unavailable and the overall exploitation probability remains uncertain, but the high CVSS score and the ability to access host files elevate the risk. Adopting standard best practices such as monitoring for anomalous file access and enforcing the principle of least privilege can reduce the likelihood of successful exploitation.
OpenCVE Enrichment