Junglewise Threat Intelligence

CVE-2026-9051: NI SystemLink Enterprise authentication bypass in Dashboard

CVE-2026-9051 · Severity: critical · CVSS 9.1 · Published 2026-05-29

Vendors: NI.

Executive brief

An authentication bypass vulnerability exists in the NI SystemLink Enterprise Dashboard, a platform used for managing engineering data and systems. An unauthenticated remote attacker can exploit this flaw to gain unauthorized access to dashboard resources, potentially leading to the theft of sensitive information or the elevation of user privileges. This could allow an attacker to view or modify critical engineering dashboards without any valid credentials.

Technical details

The vulnerability is classified as a Missing Authentication for Critical Function (CWE-306) within the NI SystemLink Enterprise Dashboard application. It allows a remote, unauthenticated attacker to bypass authentication mechanisms by sending a specially crafted HTTP request to the server. Successful exploitation can lead to information disclosure or privilege escalation specifically within the scope of Dashboard resources. The flaw affects NI SystemLink Enterprise versions 2026-04 and earlier; NI has released version 2026-05 to remediate the issue.

Affected products

  • NI SystemLink Enterprise 2026-04 and prior versions

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory
  • 2026-05-29: patched: Fixed in version 2026-05

References