CVE-2026-4130 PUBLISHED

Storage of Sensitive Information in Cleartext in NI SystemLink

Assigner: NI
Reserved: 13.03.2026 Published: 10.09.2026 Updated: 10.09.2026

There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.4

Product Status

Vendor NI
Product SystemLink
Versions Default: unaffected
  • affected from 0 to 26.5.0 (incl.)
Vendor NI
Product SystemLink Server
Versions Default: unaffected
  • affected from 0 to 26.5.0 (incl.)

References

Problem Types

  • CWE-312 Cleartext storage of sensitive information CWE

Impacts

  • CAPEC-37 Retrieve Embedded Sensitive Data