Impact
NI SystemLink and its Server component store sensitive information such as credentials or tokens in cleartext, a flaw that allows an attacker with local access to read and expose these unencrypted secrets. This directly compromises confidential data and can enable further misuse of system services, illustrating a clear confidentiality vulnerability classified as CWE‑312.
Affected Systems
The flaw exists in NI SystemLink and NI SystemLink Server in all releases from the 2026 series up to and including 2026 Q3. All earlier versions within 2026 are affected.
Risk and Exploitability
The CVSS score of 8.4 classifies this as a high‑severity flaw. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the local‑access requirement means that insiders or compromised local accounts can readily exploit the defect. Once local privileges are achieved, reading the cleartext store is straightforward, with no additional network or privilege escalation steps required.
OpenCVE Enrichment