CVE-2026-8636: IBM Datacap

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.

Affected products

  • IBM Datacap: version 9.1.7 only; version 9.1.8 only; version 9.1.9 only
  • IBM Datacap Navigator: version 9.1.7 only; version 9.1.8 only; version 9.1.9 only

Published 2026-06-22. Last modified 2026-06-26.