Junglewise Threat Intelligence

CVE-2026-9610: IBM Datacap forced browsing access control bypass

CVE-2026-9610 · Severity: low · CVSS 2.3 · Published 2026-06-22

Technologies: IBM Datacap Navigator, IBM Datacap. Vendors: IBM.

Executive brief

IBM Datacap, a document capture and data extraction platform, contains a security flaw where certain administrative or internal functions are not properly hidden. An authorized user with high-level system access could bypass the standard user interface to access restricted resources by manually entering specific web addresses. While the risk is low because it requires existing high-level permissions, it could lead to unauthorized viewing of system information.

Technical details

A direct request (forced browsing) vulnerability exists in IBM Datacap and Datacap Navigator (CWE-425). The application fails to properly enforce access controls on certain resources or functionalities that are omitted from the standard UI navigation. An attacker with high-privileged local access (PR:H) can bypass intended UI restrictions by manually crafting and requesting specific URLs. This could allow the attacker to view sensitive system resources or metadata. The vulnerability is addressed in IBM Datacap version 9.1.9 Interim Fix 008.

Affected products

  • IBM Datacap 9.1.7, 9.1.8, 9.1.9
  • IBM Datacap Navigator 9.1.7, 9.1.8, 9.1.9

Timeline

  • 2026-06-16: advisory: Initial publication by IBM
  • 2026-06-22: disclosed: NVD publication date

References

Related threats