CVE-2026-8036: Ni Ni-Pal

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.

Affected products

  • Ni Ni-Pal: up to and including 26.3.0

Published 2026-06-02. Last modified 2026-07-22.