{"api_version":"1","generated_at":"2026-06-22T19:30:04+00:00","cve":"CVE-2026-9610","urls":{"html":"https://cve.report/CVE-2026-9610","api":"https://cve.report/api/cve/CVE-2026-9610.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-9610","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-9610"},"summary":{"title":"Multiple Vulnerabilities in IBM Datacap","description":"IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-06-22 16:16:43","updated_at":"2026-06-22 18:16:52"},"problem_types":["CWE-425","CWE-425 CWE-425 Direct Request ('Forced Browsing')"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Secondary","score":"2.3","severity":"LOW","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.3,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"2.3","severity":"LOW","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":2.3,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7276609","name":"https://www.ibm.com/support/pages/node/7276609","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-9610","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9610","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"Datacap","version":"affected 9.1.7 1.8.4 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Datacap","version":"affected 9.1.8 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Datacap","version":"affected 9.1.9 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Datacap Navigator","version":"affected 9.1.7 8.2.1.0 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Datacap Navigator","version":"affected 9.1.8","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Datacap Navigator","version":"affected 9.1.9","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing IBM Datacap 9.1.9 Interim Fix 008","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-9610","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-06-22T15:57:54.703425Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-06-22T15:58:05.511Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:datacap:9.1.7:*:*:*:*:*:*:*","cpe:2.3:a:ibm:datacap:9.1.8:*:*:*:*:*:*:*","cpe:2.3:a:ibm:datacap:9.1.9:*:*:*:*:*:*:*"],"product":"Datacap","vendor":"IBM","versions":[{"lessThanOrEqual":"1.8.4","status":"affected","version":"9.1.7","versionType":"semver"},{"status":"affected","version":"9.1.8","versionType":"semver"},{"status":"affected","version":"9.1.9","versionType":"semver"}]},{"cpes":["cpe:2.3:a:ibm:datacap_navigator:9.1.7:*:*:*:*:*:*:*","cpe:2.3:a:ibm:datacap_navigator:9.1.8:*:*:*:*:*:*:*","cpe:2.3:a:ibm:datacap_navigator:9.1.9:*:*:*:*:*:*:*"],"product":"Datacap Navigator","vendor":"IBM","versions":[{"lessThanOrEqual":"8.2.1.0","status":"affected","version":"9.1.7","versionType":"semver"},{"status":"affected","version":"9.1.8"},{"status":"affected","version":"9.1.9"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.</p>"}],"value":"IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":2.3,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-425","description":"CWE-425 Direct Request ('Forced Browsing')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-06-22T14:22:34.095Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7276609"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing <a href=\"https://www.ibm.com/support/pages/ibm-datacap-version-919-interim-fix-008-readme-file\" rel=\"nofollow\">IBM Datacap 9.1.9 Interim Fix 008</a></p>"}],"value":"IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing IBM Datacap 9.1.9 Interim Fix 008"}],"title":"Multiple Vulnerabilities in IBM Datacap","x_generator":{"engine":"ibm-cvegen"}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2026-9610","datePublished":"2026-06-22T14:22:34.095Z","dateReserved":"2026-05-26T16:26:51.917Z","dateUpdated":"2026-06-22T15:58:05.511Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-06-22 16:16:43","lastModifiedDate":"2026-06-22 18:16:52","problem_types":["CWE-425","CWE-425 CWE-425 Direct Request ('Forced Browsing')"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.3,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-22T15:57:54.703425Z","id":"CVE-2026-9610","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"9610","Ordinal":"1","Title":"Multiple Vulnerabilities in IBM Datacap","CVE":"CVE-2026-9610","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"9610","Ordinal":"1","NoteData":"IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.","Type":"Description","Title":"Multiple Vulnerabilities in IBM Datacap"}]}}}