Full Report
[Control Systems] National Instruments security advisory (AV26-914)
Analysis Summary
# Vulnerability: Multiple Security Flaws in National Instruments (NI) SystemLink
## CVE Details
*Note: While the advisory specifies the vulnerabilities, the specific CVE identifiers for these 2026 findings are typically assigned upon full disclosure. The following reflects the flaw categories identified:*
- **CVE ID:** Pending/Multiple (Referenced via NI 2026 Security Update)
- **CVSS Score:** Not explicitly listed in the brief (Severity: **Critical/High** based on "Improper Access Control" designation)
- **CWE:**
- CWE-284: Improper Access Control
- CWE-312: Cleartext Storage of Sensitive Information
## Affected Systems
- **Products:**
- NI SystemLink
- NI SystemLink Server
- **Versions:** All versions prior to or equal to **2026 Q3 Patch 1**
- **Configurations:** Systems utilizing default storage configurations and standard user access control modules.
## Vulnerability Description
Two primary vulnerabilities affect the NI SystemLink environment:
1. **Improper Access Control:** A flaw in the authorization mechanism allows users to bypass intended restrictions, potentially gaining unauthorized access to system resources or administrative functions.
2. **Cleartext Storage of Sensitive Information:** The application stores sensitive data (such as credentials or configuration secrets) without encryption. An attacker with filesystem access or through the exploitation of the access control flaw could retrieve this data to escalate privileges.
## Exploitation
- **Status:** Not reported as exploited in the wild (as of advisory date).
- **Complexity:** Medium
- **Attack Vector:** Network (Remote) / Local (for cleartext data access)
## Impact
- **Confidentiality:** High (Sensitive data stored in cleartext)
- **Integrity:** High (Improper access controls may allow unauthorized modifications)
- **Availability:** Medium (Potential for service disruption via unauthorized access)
## Remediation
### Patches
National Instruments has released updates to address these flaws. Users are advised to upgrade to:
- **SystemLink 2026 Q3 Patch 2 (or later)**
- **SystemLink Server 2026 Q3 Patch 2 (or later)**
### Workarounds
- **Strict Access Control:** Implement network segmentation to ensure SystemLink servers are not exposed to the public internet.
- **Filesystem Permissions:** Restrict OS-level access to SystemLink installation directories to the minimum required service accounts to mitigate cleartext data exposure.
## Detection
- **Audit Logs:** Monitor NI SystemLink access logs for unusual user activity or unauthorized attempts to access administrative modules.
- **File Monitoring:** Monitor for unauthorized access to configuration files and database backups where sensitive information may be stored.
## References
- **National Instruments Security Updates:** hxxps[://]www[.]ni[.]com/en/support/security/available-critical-and-security-updates-for-ni-software/2026[.]html
- **NI Improper Access Control Advisory:** hxxps[://]www[.]ni[.]com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/improper-access-controls-in-ni-systemlink[.]html
- **NI Cleartext Storage Advisory:** hxxps[://]www[.]ni[.]com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/storage-of-sensitive-information-in-cleartext-in-ni-systemlink[.]html
- **Cyber Centre Advisory (AV26-914):** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/control-systems-national-instruments-security-advisory-av26-914