# CVE-2026-8059

> IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

- **CVSS:** 6.1 (MEDIUM)
- **EPSS:** 0.1%
- **CWE:** CWE-79

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-8059
Full threat coverage + IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
