CVE-2026-4130
Received
Received - Intake
Sensitive Information Disclosure in NI SystemLink
Vulnerability report for CVE-2026-4130, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-10
Last updated on: 2026-09-10
Assigner: National Instruments
Description
Description
There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.Β This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ni | systemlink | to 2026_q3 (inc) |
| ni | systemlink_server | to 2026_q3 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-312 | The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere. |