CVE-2026-18485

Summary

There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.  This may allow a local, authenticated user to escalate privileges and execute arbitrary code.  This vulnerability affects NI-PAL 26.3.1 and prior versions running on Microsoft Windows.

Affected Software

VendorProductVersion RangeStatus
NINI-PAL0 <= 26.3.1affected

Weaknesses

  • CWE-1285: CWE-1285 Improper validation of specified index, position, or offset in input

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References