IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.
PUBLISHED5.2ApplicationCWE-425
Multiple Vulnerabilities in IBM Datacap
Problem type
Affected products
IBM
Datacap
<= 1.8.4 - AFFECTED
9.1.8 - AFFECTED
9.1.9 - AFFECTED
Datacap Navigator
<= 8.2.1.0 - AFFECTED
9.1.8 - AFFECTED
9.1.9 - AFFECTED
References
GitHub Security Advisories
GHSA-gc5m-j868-gqpq
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes...
https://github.com/advisories/GHSA-gc5m-j868-gqpqIBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-9610Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-9610",
"assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"assignerShortName": "ibm",
"dateUpdated": "2026-06-22T15:58:05.511Z",
"dateReserved": "2026-05-26T16:26:51.917Z",
"datePublished": "2026-06-22T14:22:34.095Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"shortName": "ibm",
"dateUpdated": "2026-06-22T14:22:34.095Z"
},
"title": "Multiple Vulnerabilities in IBM Datacap",
"descriptions": [
{
"lang": "en",
"value": "IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "<p>IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.</p>"
}
]
}
],
"affected": [
{
"vendor": "IBM",
"product": "Datacap",
"cpes": [
"cpe:2.3:a:ibm:datacap:9.1.7:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:datacap:9.1.8:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:datacap:9.1.9:*:*:*:*:*:*:*"
],
"versions": [
{
"version": "9.1.7",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "1.8.4"
},
{
"version": "9.1.8",
"status": "affected",
"versionType": "semver"
},
{
"version": "9.1.9",
"status": "affected",
"versionType": "semver"
}
]
},
{
"vendor": "IBM",
"product": "Datacap Navigator",
"cpes": [
"cpe:2.3:a:ibm:datacap_navigator:9.1.7:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:datacap_navigator:9.1.8:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:datacap_navigator:9.1.9:*:*:*:*:*:*:*"
],
"versions": [
{
"version": "9.1.7",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "8.2.1.0"
},
{
"version": "9.1.8",
"status": "affected"
},
{
"version": "9.1.9",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-425 Direct Request ('Forced Browsing')",
"cweId": "CWE-425",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://www.ibm.com/support/pages/node/7276609",
"tags": [
"vendor-advisory",
"patch"
]
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 2.3,
"baseSeverity": "LOW"
}
}
],
"solutions": [
{
"lang": "en",
"value": "IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing IBM Datacap 9.1.9 Interim Fix 008",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "<p>IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing <a href=\"https://www.ibm.com/support/pages/ibm-datacap-version-919-interim-fix-008-readme-file\" rel=\"nofollow\">IBM Datacap 9.1.9 Interim Fix 008</a></p>"
}
]
}
]
},
"adp": [
{
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2026-06-22T15:58:05.511Z"
},
"title": "CISA ADP Vulnrichment",
"metrics": [
{}
]
}
]
}
}