Cross-Site Scripting Vulnerability in IBM Datacap and Datacap Navigator
CVE-2026-8059

6.1MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
22 June 2026

What is CVE-2026-8059?

IBM Datacap and Datacap Navigator versions 9.1.7, 9.1.8, and 9.1.9 are susceptible to cross-site scripting attacks. This vulnerability can be exploited by an unauthenticated attacker who embeds arbitrary JavaScript code in the web user interface. Such malicious input can alter the intended functionality of the application, leading to potential leakage of credentials during trusted sessions.

Affected Version(s)

Datacap 9.1.7 <= 1.8.4

Datacap 9.1.8

Datacap 9.1.9

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.