Home

Description

There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or information disclosure. Successful exploitation requires an attacker to send a specially crafted HTTP request. This vulnerability affects NI SystemLink Enterprise 2026-04 and prior versions.

PUBLISHED Reserved 2026-05-19 | Published 2026-05-29 | Updated 2026-05-29 | Assigner NI




CRITICAL: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-306 Missing authentication for critical function

Product status

Default status
unaffected

Any version
affected

References

www.ni.com/...vulnerability-in-ni-systemlink-enterprise.html

cve.org (CVE-2026-9051)

nvd.nist.gov (CVE-2026-9051)

Download JSON