Executive brief
NI SystemLink is a software platform used for managing and monitoring networked systems and devices. An authenticated attacker with limited privileges can bypass access controls to read sensitive host operating system files and directories that should be restricted, potentially exposing configuration data, credentials, or other sensitive system information.
Technical details
This is an improper access control (CWE-862: Missing Authorization) vulnerability in NI SystemLink and NI SystemLink Server. An authenticated user with limited privileges can access host OS files and directories that should be restricted, indicating insufficient authorization checks in the file access control logic. The vulnerability requires network access and an authenticated session (PR:L), with no user interaction required. An attacker can achieve high confidentiality and integrity impact. The fix is to upgrade to NI SystemLink 2026 Q3 or later.
Affected products
- NI SystemLink prior to 2026 Q3
- NI SystemLink Server prior to 2026 Q3
Timeline
- 2026-09-10: disclosed
- 2026-09-17: advisory