CVE-2026-9610
published 2026-06-22CVE-2026-9610: IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.19%
8.7th percentile
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | datacap | — | — |
| ibm | datacap | — | — |
| ibm | datacap | — | — |
| ibm | datacap | 9.1.7 – 1.8.4 | — |
| ibm | datacap_navigator | — | — |
| ibm | datacap_navigator | — | — |
| ibm | datacap_navigator | — | — |
| ibm | datacap_navigator | 9.1.7 – 8.2.1.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, b
ghsa_unreviewed·2026-06-22
CVE-2026-9610 [LOW] CWE-425 IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, b
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.
VulDB
IBM Datacap/Datacap Navigator up to 1.8.4/9.1.8/9.1.9 direct request
vuldb·2026-06-22·CVSS 2.3
CVE-2026-9610 [LOW] IBM Datacap/Datacap Navigator up to 1.8.4/9.1.8/9.1.9 direct request
A vulnerability categorized as problematic has been discovered in IBM Datacap and Datacap Navigator up to 1.8.4/9.1.8/9.1.9. This vulnerability affects unknown code. Such manipulation leads to direct request.
This vulnerability is documented as CVE-2026-9610. The attack needs to be performed locally. There is not any exploit available.
It is advisable to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-22
Published