Junglewise Threat Intelligence

CVE-2026-8059: IBM Datacap cross-site scripting in Navigator Web UI

CVE-2026-8059 · Severity: medium · CVSS 6.1 · Published 2026-06-22

Technologies: IBM Datacap Navigator, IBM Datacap. Vendors: IBM.

Executive brief

IBM Datacap, a document capture and data extraction platform, is vulnerable to a security flaw in its web interface. An attacker could trick a user into executing malicious scripts, which may allow the attacker to steal login credentials or modify what the user sees on the screen. This could compromise sensitive business data processed by the system.

Technical details

IBM Datacap and Datacap Navigator versions 9.1.7, 9.1.8, and 9.1.9 are affected by a cross-site scripting (XSS) vulnerability (CWE-79). The flaw exists in the Web UI component due to improper neutralization of user-supplied input during web page generation. Although the CVSS vector indicates a local attack vector (AV:L), the nature of XSS typically involves a remote attacker tricking a local user into interacting with a malicious link or crafted input. Successful exploitation allows an unauthenticated attacker to embed arbitrary JavaScript code within a trusted session, potentially leading to the disclosure of session credentials or unauthorized modification of the application's functionality. IBM has released Datacap 9.1.9 Interim Fix 008 to address this issue.

Affected products

  • IBM Datacap 9.1.7, 9.1.8, 9.1.9
  • IBM Datacap Navigator 9.1.7, 9.1.8, 9.1.9

Timeline

  • 2026-06-16: advisory: Initial publication by IBM
  • 2026-06-22: disclosed: NVD publication date

References

Related threats