CVE-2026-9051 PUBLISHED

Authentication Bypass Vulnerability in NI SystemLink Enterprise

Assigner: NI
Reserved: 19.05.2026 Published: 29.05.2026 Updated: 29.05.2026

There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or information disclosure.  Successful exploitation requires an attacker to send a specially crafted HTTP request.  This vulnerability affects NI SystemLink Enterprise 2026-04 and prior versions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor NI
Product SystemLink Enterprise
Versions Default: unaffected
  • affected from 0 to 2026-04 (incl.)

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE

Impacts

  • CAPEC-115 Authentication Bypass