CVE-2026-8636
Ibm Datacap 9.1.7 … 9.1.9
Raw vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NSummary
CVE-2026-8636 is a medium-severity Cleartext Storage of Sensitive Information in Memory (CWE-316) vulnerability in Ibm Datacap. Its CVSS base score is 5.5 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique OS Credential Dumping (T1003); ranked at the 4th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SC-39 (Process Isolation) and SI-16 (Memory Protection) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-38283
Vulnerability Data
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application…
more
and access sensitive data in the database.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Vulnerability enables direct retrieval of passwords/keys from process memory, facilitating OS-level credential dumping techniques.
Likely ATT&CK TechniquesAI
Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly implements memory protection safeguards to prevent unauthorized disclosure of sensitive data such as passwords and cryptographic keys stored in cleartext.
Enforces process isolation so that an attacker cannot access memory belonging to other processes containing passwords or keys.
Enforces access control decisions that restrict which subjects can read or retrieve sensitive credential material from memory.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Explicitly calls for removing confidential data from process memory, directly mitigating cleartext storage.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect cleartext secrets in memory dumps or debug output.
Secure deletion practices reduce residual cleartext after use, but do not prevent initial storage.
DLP tooling can monitor and block processes that leave sensitive data unencrypted in memory.
Cryptographic controls can mandate encryption of sensitive data in memory, directly reducing cleartext exposure.
Secure-SDLC processes include memory-handling reviews that catch this weakness.
Secure-coding standards explicitly require avoiding plaintext storage of secrets in RAM.