Executive brief
NI SystemLink and NI SystemLink Server store sensitive information in cleartext on disk, allowing an attacker with local access to the system to read and steal this data. This exposes credentials, API keys, and other secrets that could be used to compromise connected systems or access sensitive configuration data.
Technical details
This vulnerability is a cleartext storage of sensitive information issue (CWE-312) affecting NI SystemLink and NI SystemLink Server. The root cause is that sensitive data such as credentials, tokens, and configuration secrets are stored unencrypted on the filesystem where the application is deployed. An attacker with local access and low privileges (user-level) can read these stored secrets without requiring elevated permissions. Exploitation allows an attacker to extract sensitive information and use it to compromise connected systems or gain unauthorized access to protected resources. The vulnerability is patched in version 2026 Q3 and later; users should upgrade immediately via NI Package Manager or Software Downloads.
Affected products
- National Instruments SystemLink prior to 2026 Q3
- National Instruments SystemLink Server prior to 2026 Q3
Timeline
- 2026-09-10: disclosed: CVE published on NVD
- 2026-Q3: patched: Fix available in NI SystemLink 2026 Q3 or later