# CVE-2026-8636

## Summary

- **CVE ID:** CVE-2026-8636
- **Severity:** MEDIUM
- **CVSS Score:** 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-316
- **Published:** Jun 22, 2026
- **Last Modified:** Jun 22, 2026

## Description

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.

## Affected Products

- IBM — Datacap (9.1.7)
- IBM — Datacap (9.1.8)
- IBM — Datacap (9.1.9)
- IBM — Datacap Navigator (9.1.7)
- IBM — Datacap Navigator (9.1.8)
- IBM — Datacap Navigator (9.1.9)

## References

- [CNA](https://www.ibm.com/support/pages/node/7276609)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 9.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._