CVE-2026-9610

EUVD-2026-38287
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.
Forced Browsing
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.3 LOW
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 8.71%
Affected Products (NVD)
VendorProductVersion
ibmdatacap
9.1.7
ibmdatacap
9.1.8
ibmdatacap
9.1.9
ibmdatacap_navigator
9.1.7
ibmdatacap_navigator
9.1.8
ibmdatacap_navigator
9.1.9
𝑥
= Vulnerable software versions