CVE-2026-4129
moderateImproper access control in NI SystemLink exposes restricted host OS files
CVE-2026-4129 is a missing-authorization (CWE-862) flaw in NI SystemLink in which certain requests are not properly checked against the requester's privileges. An authenticated user with limited privileges can send network requests to the SystemLink server and gain access to files and directories on the host operating system that should be restricted. According to the CVSS 4.0 vector, the attack requires network access to the service and no user interaction, and yields high confidentiality and integrity impact on the host, meaning an attacker can likely read and potentially modify or influence sensitive OS-level files. Anyone running NI SystemLink or NI SystemLink Server version 2026 Q3 or earlier is affected. There is currently no known public proof-of-concept, it is not in the CISA KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Upgrade NI SystemLink / NI SystemLink Server to a version later than 2026 Q3 once NI's advisory identifies the fixed release. Until patched, restrict which low-privileged accounts can reach the server, limit network exposure of SystemLink hosts to trusted lab networks, and audit for unexpected file access or changes on the server host.
| NI (National Instruments, an Emerson company) NI SystemLink | 2026 Q3 and prior versions |
| NI (National Instruments, an Emerson company) NI SystemLink Server | 2026 Q3 and prior versions |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
- Weakness
- CWE-862
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.