CVE-2026-8036

Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ni:ni-pal:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:ni:linux_real-time:-:*:*:*:*:*:*:*

History

05 Jun 2026, 15:10

Type Values Removed Values Added
CPE cpe:2.3:a:ni:ni-pal:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:ni:linux_real-time:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
First Time Ni linux Real-time
Ni
Linux linux Kernel
Microsoft windows
Linux
Microsoft
Ni ni-pal
References () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/invalid-input-validation-vulnerabilities-in-ni-pal.html - () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/invalid-input-validation-vulnerabilities-in-ni-pal.html - Vendor Advisory

02 Jun 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-02 20:16

Updated : 2026-06-05 15:10


NVD link : CVE-2026-8036

Mitre link : CVE-2026-8036

CVE.ORG link : CVE-2026-8036


JSON object : View

Products Affected

ni

  • linux_real-time
  • ni-pal

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-1285

Improper Validation of Specified Index, Position, or Offset in Input