National InstrumentsCVE-2026-4129
National Instruments NI SystemLink: improper access control
High8.6CVE-2026-4129 · Published Sep 10, 2026 · updated Sep 16, 2026
There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SystemLink Product | < 26.5.0 | 26.5.0 |
| SystemLink Server Product | < 26.5.0 | 26.5.0 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
More National Instruments advisories
All National Instruments| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 10 | National Instruments SystemLink: information disclosure | High8.4 | 26.5.0+1 more |
| Sep 3 | National Instruments DASYLab: out-of-bounds write | High8.5 | 2026.0.0 |
| Sep 3 | National Instruments DASYLab: out-of-bounds read | High8.5 | 2026.0.0 |
| Sep 3 | National Instruments DASYLab: out-of-bounds read | High8.6 | 2026.0.0 |
| Sep 3 | National Instruments DASYLab: out-of-bounds read | High8.5 | 2026.0.0 |
| Sep 3 | National Instruments DASYLab: out-of-bounds write | High8.5 | 2026.0.0 |