---
id: CVE-2026-4129
title: >-
  There is an improper access control vulnerability in NI SystemLink that may
  allow an authenticated user with limited privileges to access host operating
  system files and directories that should be restricted
summary: >-
  There is an improper access control vulnerability in NI SystemLink that may
  allow an authenticated user with limited privileges to access host operating
  system files and directories that should be restricted. This vulnerability
  affects N…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-862
vendor: NI
product: SystemLink
affected:
  - SystemLink <= 26.5.0
  - systemlink_server <= 26.5.0
published: '2026-09-10'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T17:17:19.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4129'
references:
  - url: >-
      https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/improper-access-controls-in-ni-systemlink.html
    label: security@ni.com
tags:
  - nvd
  - cve.org
epss: 0.0035
epssPercentile: 0.25929
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-11T00:00:00+00:00'
ingestedAt: '2026-09-14T15:16:39.165Z'
---

## Overview

There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
