Description
There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3.
Published: 2026-09-10
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality breach
Action: Patch Now
AI Analysis

Impact

NI SystemLink and its Server component store sensitive credentials or tokens in cleartext, allowing a local attacker to read and expose these unencrypted secrets. The flaw directly compromises confidentiality and is classified as CWE‑312. The vulnerability affects all releases prior to 2026 Q3.

Affected Systems

The flaw exists in NI SystemLink and NI SystemLink Server in all releases prior to 2026 Q3. All earlier versions before 2026 Q3 are affected.

Risk and Exploitability

The CVSS score of 8.4 classifies this as a high‑severity flaw. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the local‑access requirement means that insiders or compromised local accounts can readily exploit the defect. Once local privileges are achieved, reading the cleartext store is straightforward, with no additional network or privilege escalation steps required.

Generated by OpenCVE AI on September 21, 2026 at 05:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest update from NI that eliminates cleartext storage of sensitive data
  • Where a patch is not yet available, configure the system to store credentials or tokens in encrypted form, following NI guidance
  • Enforce strict local access controls and apply least privilege principles for users interacting with the system

Generated by OpenCVE AI on September 21, 2026 at 05:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions. There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3.

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
Title Storage of Sensitive Information in Cleartext in NI SystemLink
First Time appeared Ni
Ni systemlink
Ni systemlink Server
Weaknesses CWE-312
CPEs cpe:2.3:a:ni:systemlink:*:*:*:*:*:*:*:*
cpe:2.3:a:ni:systemlink_server:*:*:*:*:*:*:*:*
Vendors & Products Ni
Ni systemlink
Ni systemlink Server
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ni Systemlink Systemlink Server
cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2026-09-16T16:24:48.195Z

Reserved: 2026-03-13T14:11:51.198Z

Link: CVE-2026-4130

cve-icon Vulnrichment

Updated: 2026-09-10T16:41:28.377Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T16:17:14.227

Modified: 2026-09-16T17:17:19.360

Link: CVE-2026-4130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:30:07Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information