CVE-2026-4129: Improper Access Controls in NI SystemLink
There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker must already be authenticated as a user with limited privileges. No user interaction is required, and the vulnerability is reachable over the network.
Which deployments should be considered affected?
NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions are affected. Organizations using either product at those versions should assess exposure.
What could a successful attacker access?
A limited-privilege authenticated user may be able to access host operating system files and directories that are intended to be restricted. The reported impact includes high confidentiality and integrity impact.