CVE-2026-8059 PUBLISHED

Multiple Vulnerabilities in IBM Datacap

Assigner: ibm
Reserved: 06.05.2026 Published: 22.06.2026 Updated: 22.06.2026

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CVSS Score: 6.1

Product Status

Vendor IBM
Product Datacap
Versions
  • affected from 9.1.7 to 1.8.4 (incl.)
  • Version 9.1.8 is affected
  • Version 9.1.9 is affected
Vendor IBM
Product Datacap Navigator
Versions
  • affected from 9.1.7 to 8.2.1.0 (incl.)
  • Version 9.1.8 is affected
  • Version 9.1.9 is affected

Solutions

IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing IBM Datacap 9.1.9 Interim Fix 008

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE