CVE-2026-9610: Multiple Vulnerabilities in IBM Datacap
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.
Other sources
IBM Datacap exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Datacapto a version that resolves this vulnerability.Fixed in 9.1.9Patch Interim Fix 008 - Upgrade
Upgrade
IBM Datacap Navigatorto a version that resolves this vulnerability.Fixed in 9.1.9Patch Interim Fix 008
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9610?
The severity of CVE-2026-9610 is medium with a score of 5.3.
How do I fix CVE-2026-9610?
To fix CVE-2026-9610, upgrade to a patched version of IBM Datacap or IBM Datacap Navigator that addresses this vulnerability.
What systems are affected by CVE-2026-9610?
CVE-2026-9610 affects IBM Datacap versions 9.1.7, 9.1.8, and 9.1.9, as well as IBM Datacap Navigator versions 9.1.7, 9.1.8, and 9.1.9.
What kind of access does CVE-2026-9610 allow?
CVE-2026-9610 allows unauthorized access to resources or functionality by requesting URLs directly, bypassing access controls.
What is the potential impact of CVE-2026-9610?
The potential impact of CVE-2026-9610 includes exposure of sensitive resources, which could lead to data leakage or unauthorized actions within the IBM Datacap application.