CVE-2026-8059
published 2026-06-22CVE-2026-8059: IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allows an…
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.17%
6.5th percentile
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | datacap | — | — |
| ibm | datacap | — | — |
| ibm | datacap | — | — |
| ibm | datacap | 9.1.7 – 1.8.4 | — |
| ibm | datacap_navigator | — | — |
| ibm | datacap_navigator | — | — |
| ibm | datacap_navigator | — | — |
| ibm | datacap_navigator | 9.1.7 – 8.2.1.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting.
ghsa_unreviewed·2026-06-22
CVE-2026-8059 [MEDIUM] CWE-79 IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting.
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
VulDB
IBM Datacap/Datacap Navigator up to 1.8.4/9.1.8/9.1.9 cross site scripting (EUVD-2026-38282)
vuldb·2026-06-22·CVSS 6.1
CVE-2026-8059 [MEDIUM] IBM Datacap/Datacap Navigator up to 1.8.4/9.1.8/9.1.9 cross site scripting (EUVD-2026-38282)
A vulnerability labeled as problematic has been found in IBM Datacap and Datacap Navigator up to 1.8.4/9.1.8/9.1.9. Impacted is an unknown function. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2026-8059. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-22
Published