CVE-2026-8036
Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.4
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.11%
- CWE
- CWE-1285
- Published
- 2026-06-02
- Last modified
- 2026-06-04
Affected products
- NI NI-PAL
Weakness type
Related vulnerabilities
- CVE-2026-31912 — OOBR in libpcap before 1.10.7
- CVE-2026-53530 — ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
- CVE-2026-14479 — Denial of Service in Autodesk Installer IPC Channel
- CVE-2026-18485 — Local Privilege Escalation in NI-PAL
- CVE-2026-12681 — Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google...
- CVE-2026-45352 — cpp-httplib DoS: Negative chunk-size in chunked Transfer-Encoding
- CVE-2026-9100 — Heap memory out of bounds read and crash in C Driver legacy GridFS file reader
- CVE-2026-33557 — Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication