CVE-2026-8636: Multiple Vulnerabilities in IBM Datacap
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.
Other sources
IBM Datacap allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Datacapto a version that resolves this vulnerability.Fixed in 9.1.9Patch Interim Fix 008 - Upgrade
Upgrade
IBM Datacap Navigatorto a version that resolves this vulnerability.Fixed in 9.1.9Patch Interim Fix 008
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8636?
The severity of CVE-2026-8636 is rated as high, with a score of 7.5.
How do I fix CVE-2026-8636?
To fix CVE-2026-8636, update IBM Datacap and IBM Datacap Navigator to the latest patched versions.
What security risks are associated with CVE-2026-8636?
CVE-2026-8636 allows attackers to retrieve user passwords and cryptographic keys from memory, potentially compromising sensitive data.
Which versions of IBM Datacap are affected by CVE-2026-8636?
IBM Datacap versions 9.1.7, 9.1.8, and 9.1.9 are affected by CVE-2026-8636.
Can CVE-2026-8636 lead to a data breach?
Yes, CVE-2026-8636 can lead to a data breach if an attacker successfully retrieves credentials and gains unauthorized access to the application.