CVE-2026-4130
Received Received - Intake

Sensitive Information Disclosure in NI SystemLink

Vulnerability report for CVE-2026-4130, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: National Instruments

Description

There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.Β  This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-10
AI Q&A
2026-09-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ni systemlink to 2026_q3 (inc)
ni systemlink_server to 2026_q3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-312 The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-4130 is a vulnerability in NI SystemLink and NI SystemLink Server versions up to 2026 Q3 where sensitive information is stored in cleartext. This means data is saved without encryption, allowing local attackers with access to retrieve it.

Detection Guidance

This vulnerability involves sensitive information stored in cleartext in NI SystemLink. Detection requires checking for unencrypted sensitive data in system files or logs. Review configuration files and log directories for plaintext credentials or sensitive information. No specific commands are provided in the available resources.

Impact Analysis

An attacker with local access could obtain sensitive information stored by the system. This may lead to data breaches, unauthorized access to confidential data, or further exploitation depending on the exposed information.

Compliance Impact

Storing sensitive data in cleartext violates compliance requirements for GDPR and HIPAA, which mandate encryption for personal and health data. This vulnerability could result in non-compliance penalties and increased exposure to legal risks.

Mitigation Strategies

Upgrade to NI SystemLink 2026 Q3 Patch 1 or later to address the vulnerability. NI SystemLink Enterprise is not impacted, so no action is required for that product.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-4130. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart