ZeroHour

CVE-2026-4130

Cleartext storage of sensitive information in NI SystemLink

CVSS 4.0
8.4 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-4130 is a cleartext storage of sensitive information flaw (CWE-312) in NI SystemLink, where sensitive data such as credentials or secrets is written to disk unencrypted. An attacker who gains local access to a deployed system, with only low privileges and no user interaction required, can read this information directly from the system's storage. Successful exploitation exposes whatever sensitive data the product stores in the clear, which could enable further access to the SystemLink environment or connected infrastructure. All NI SystemLink and NI SystemLink Server deployments at version 2026 Q3 or earlier are affected. There is no evidence of active exploitation: the flaw is not in CISA KEV and no public proof-of-concept is known.

What to do: Upgrade NI SystemLink and NI SystemLink Server to a release newer than 2026 Q3 per NI's advisory (a specific fixed version was not provided in this data). Restrict local access to SystemLink hosts, and audit the installation directories and configuration stores for plaintext credentials, which should be rotated if found.

Affected
NI (National Instruments) NI SystemLink2026 Q3 and prior versions
NI (National Instruments) NI SystemLink Server2026 Q3 and prior versions
Estimated exposure
unknown (likely low thousands of on-premises test/monitoring deployments) — No public install counts or internet-exposure scan data are available; NI SystemLink is enterprise test-and-measurement software typically deployed on-premises at manufacturing and test organizations rather than exposed to the internet,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.

Weakness
CWE-312
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.