2026-06-22 14:22CVE-2026-9610ibm
PUBLISHED5.2ApplicationCWE-425

Multiple Vulnerabilities in IBM Datacap

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.

Problem type

Affected products

IBM

Datacap

<= 1.8.4 - AFFECTED

9.1.8 - AFFECTED

9.1.9 - AFFECTED

Datacap Navigator

<= 8.2.1.0 - AFFECTED

9.1.8 - AFFECTED

9.1.9 - AFFECTED

References

GitHub Security Advisories

GHSA-gc5m-j868-gqpq

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes...

https://github.com/advisories/GHSA-gc5m-j868-gqpq

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-9610
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-9610",
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "dateUpdated": "2026-06-22T15:58:05.511Z",
    "dateReserved": "2026-05-26T16:26:51.917Z",
    "datePublished": "2026-06-22T14:22:34.095Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm",
        "dateUpdated": "2026-06-22T14:22:34.095Z"
      },
      "title": "Multiple Vulnerabilities in IBM Datacap",
      "descriptions": [
        {
          "lang": "en",
          "value": "IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<p>IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.</p>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "IBM",
          "product": "Datacap",
          "cpes": [
            "cpe:2.3:a:ibm:datacap:9.1.7:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:datacap:9.1.8:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:datacap:9.1.9:*:*:*:*:*:*:*"
          ],
          "versions": [
            {
              "version": "9.1.7",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "1.8.4"
            },
            {
              "version": "9.1.8",
              "status": "affected",
              "versionType": "semver"
            },
            {
              "version": "9.1.9",
              "status": "affected",
              "versionType": "semver"
            }
          ]
        },
        {
          "vendor": "IBM",
          "product": "Datacap Navigator",
          "cpes": [
            "cpe:2.3:a:ibm:datacap_navigator:9.1.7:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:datacap_navigator:9.1.8:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:datacap_navigator:9.1.9:*:*:*:*:*:*:*"
          ],
          "versions": [
            {
              "version": "9.1.7",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "8.2.1.0"
            },
            {
              "version": "9.1.8",
              "status": "affected"
            },
            {
              "version": "9.1.9",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-425 Direct Request ('Forced Browsing')",
              "cweId": "CWE-425",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7276609",
          "tags": [
            "vendor-advisory",
            "patch"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "availabilityImpact": "NONE",
            "baseScore": 2.3,
            "baseSeverity": "LOW"
          }
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "value": "IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing IBM Datacap 9.1.9 Interim Fix 008",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<p>IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing <a href=\"https://www.ibm.com/support/pages/ibm-datacap-version-919-interim-fix-008-readme-file\" rel=\"nofollow\">IBM Datacap 9.1.9 Interim Fix 008</a></p>"
            }
          ]
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2026-06-22T15:58:05.511Z"
        },
        "title": "CISA ADP Vulnrichment",
        "metrics": [
          {}
        ]
      }
    ]
  }
}