---
id: CVE-2026-4130
title: >-
  There is a storage of sensitive information in cleartext vulnerability in NI
  SystemLink
summary: "There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.\_ This vulnerability af…"
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-312
vendor: NI
product: SystemLink
affected:
  - SystemLink < 26.5.0
  - systemlink_server < 26.5.0
published: '2026-09-10'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T17:17:19.360'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4130'
references:
  - url: >-
      https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/storage-of-sensitive-information-in-cleartext-in-ni-systemlink.html
    label: security@ni.com
tags:
  - nvd
  - cve.org
epss: 0.00075
epssPercentile: 0.00105
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-11T00:00:00+00:00'
ingestedAt: '2026-09-14T15:23:07.483Z'
---

## Overview

There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
