Description
There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
Published: 2026-09-10
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality breach
Action: Patch Now
AI Analysis

Impact

NI SystemLink and its Server component store sensitive information such as credentials or tokens in cleartext, a flaw that allows an attacker with local access to read and expose these unencrypted secrets. This directly compromises confidential data and can enable further misuse of system services, illustrating a clear confidentiality vulnerability classified as CWE‑312.

Affected Systems

The flaw exists in NI SystemLink and NI SystemLink Server in all releases from the 2026 series up to and including 2026 Q3. All earlier versions within 2026 are affected.

Risk and Exploitability

The CVSS score of 8.4 classifies this as a high‑severity flaw. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the local‑access requirement means that insiders or compromised local accounts can readily exploit the defect. Once local privileges are achieved, reading the cleartext store is straightforward, with no additional network or privilege escalation steps required.

Generated by OpenCVE AI on September 10, 2026 at 17:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest update from NI that eliminates cleartext storage of sensitive data
  • Where a patch is not yet available, configure the system to store credentials or tokens in encrypted form, following NI guidance
  • Enforce strict local access controls and apply least privilege principles for users interacting with the system

Generated by OpenCVE AI on September 10, 2026 at 17:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
Title Storage of Sensitive Information in Cleartext in NI SystemLink
First Time appeared Ni
Ni systemlink
Ni systemlink Server
Weaknesses CWE-312
CPEs cpe:2.3:a:ni:systemlink:*:*:*:*:*:*:*:*
cpe:2.3:a:ni:systemlink_server:*:*:*:*:*:*:*:*
Vendors & Products Ni
Ni systemlink
Ni systemlink Server
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ni Systemlink Systemlink Server
cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2026-09-10T16:41:31.503Z

Reserved: 2026-03-13T14:11:51.198Z

Link: CVE-2026-4130

cve-icon Vulnrichment

Updated: 2026-09-10T16:41:28.377Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T16:17:14.227

Modified: 2026-09-10T19:55:45.477

Link: CVE-2026-4130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:15:17Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information