Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.
References
Configurations
Configuration 1 (hide)
| AND |
|
History
05 Jun 2026, 15:10
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:ni:ni-pal:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:ni:linux_real-time:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| First Time |
Ni linux Real-time
Ni Linux linux Kernel Microsoft windows Linux Microsoft Ni ni-pal |
|
| References | () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/invalid-input-validation-vulnerabilities-in-ni-pal.html - Vendor Advisory |
02 Jun 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-02 20:16
Updated : 2026-06-05 15:10
NVD link : CVE-2026-8036
Mitre link : CVE-2026-8036
CVE.ORG link : CVE-2026-8036
JSON object : View
Products Affected
ni
- linux_real-time
- ni-pal
microsoft
- windows
linux
- linux_kernel
CWE
CWE-1285
Improper Validation of Specified Index, Position, or Offset in Input
