CVE-2026-8036

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
02/06/2026
Last modified:
22/07/2026

Description

Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ni:ni-pal:*:*:*:*:*:*:*:* 26.3.0 (including)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:ni:linux_real-time:-:*:*:*:*:*:*:*