CVE-2026-9610 PUBLISHED

Multiple Vulnerabilities in IBM Datacap

Assigner: ibm
Reserved: 26.05.2026 Published: 22.06.2026 Updated: 22.06.2026

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 2.3

Product Status

Vendor IBM
Product Datacap
Versions
  • affected from 9.1.7 to 1.8.4 (incl.)
  • Version 9.1.8 is affected
  • Version 9.1.9 is affected
Vendor IBM
Product Datacap Navigator
Versions
  • affected from 9.1.7 to 8.2.1.0 (incl.)
  • Version 9.1.8 is affected
  • Version 9.1.9 is affected

Solutions

IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing IBM Datacap 9.1.9 Interim Fix 008

References

Problem Types

  • CWE-425 Direct Request ('Forced Browsing') CWE