CVE-2026-8036 Details
Description
Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.
A vulnerability exists in NI-PAL versions through 26.3.0 on Windows, Linux, and Linux Real-Time. It involves improper input validation that may enable a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation.
Users are advised to upgrade to NI-PAL version 26.3.1 or later. For Windows, this can be done by installing the NI-VISA 2026 Q2 Patch 1 or later. On Linux, users should install the NI Linux Device Drivers 2026 Q2 or later. For NI Linux Real-Time, NI Linux RT System Image 2026 Q2 or later should be installed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1285 | Improper Validation of Specified Index, Position, or Offset in Input | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ni ni-pal | <= 26.3.0 |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| ni linux real-time | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | Initial Analysis | [email protected] |
| Jun 2, 2026 | New CVE Received | [email protected] |