CVE-2026-8636
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.5
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.20%
- CWE
- CWE-316
- Published
- 2026-06-22
- Last modified
- 2026-06-22
Affected products
- IBM Datacap
- IBM Datacap
- IBM Datacap
- IBM Datacap Navigator
- IBM Datacap Navigator
- IBM Datacap Navigator
Weakness type
Related vulnerabilities
- CVE-2026-53604 — nebula-mesh: CA private key not zeroized on web mobile-bundle error paths
- CVE-2026-75137 — UpSignOn < 7.19.0 Sensitive Data Exposure in Process Memory after Lock
- CVE-2026-75135 — UpSignOn < 7.19.0 Sensitive Key Retention in Memory
- CVE-2026-27875 — Simplex Incident Manager Clear Test
- CVE-2026-0857 — Cleartext Storage of Sensitive Information in Memory vulnerability in Mesalvo Meona Client Launcher...
- CVE-2026-24319 — Information Disclosure Vulnerability in SAP Business One (B1 Client Memory Dump Files)
- CVE-2025-61713 — A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM...
- CVE-2025-4618 — Prisma Browser: Sensitive Information Disclosure Vulnerability in Prisma Browser