Cross-Site Scripting Vulnerability in IBM Common Licensing Agent
CVE-2026-1025

6.1MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
18 September 2026

What is CVE-2026-1025?

The vulnerability in IBM Common Licensing Agent and ART products enables attackers to exploit cross-site scripting flaws. This allows unauthorized users to inject arbitrary JavaScript into the web interface, which can alter the expected functionality and potentially lead to the disclosure of sensitive credentials during a trusted session.

Affected Version(s)

Common Licensing Agent 9.0

Common Licensing Agent 9.0.0.1

Common Licensing Agent 9.0.0.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.