CVE-2026-4129 PUBLISHED

Improper Access Controls in NI SystemLink

Assigner: NI
Reserved: 13.03.2026 Published: 10.09.2026 Updated: 10.09.2026

There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor NI
Product SystemLink
Versions Default: unaffected
  • affected from 0 to 26.5.0 (incl.)
Vendor NI
Product SystemLink Server
Versions Default: unaffected
  • affected from 0 to 26.5.0 (incl.)

References

Problem Types

  • CWE-862: Missing Authorization CWE

Impacts

  • CAPEC-115 Authentication Bypass