Junglewise Threat Intelligence

CVE-2026-4129: NI SystemLink improper access control vulnerability

CVE-2026-4129 · Severity: high · CVSS 8.1 · Published 2026-09-10

Vendors: NI.

Executive brief

NI SystemLink is a software platform used for managing and monitoring networked systems and devices. An authenticated attacker with limited privileges can bypass access controls to read sensitive host operating system files and directories that should be restricted, potentially exposing configuration data, credentials, or other sensitive system information.

Technical details

This is an improper access control (CWE-862: Missing Authorization) vulnerability in NI SystemLink and NI SystemLink Server. An authenticated user with limited privileges can access host OS files and directories that should be restricted, indicating insufficient authorization checks in the file access control logic. The vulnerability requires network access and an authenticated session (PR:L), with no user interaction required. An attacker can achieve high confidentiality and integrity impact. The fix is to upgrade to NI SystemLink 2026 Q3 or later.

Affected products

  • NI SystemLink prior to 2026 Q3
  • NI SystemLink Server prior to 2026 Q3

Timeline

  • 2026-09-10: disclosed
  • 2026-09-17: advisory

References