Cross-Site Scripting Vulnerability in IBM Common Licensing Agent
CVE-2026-1029

5.4MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
18 September 2026

What is CVE-2026-1029?

The IBM Common Licensing Agent and its related products are susceptible to a cross-site scripting (XSS) vulnerability. This flaw allows attackers to inject arbitrary JavaScript code into the Web UI, potentially compromising user credentials during a trusted session. Such XSS vulnerabilities can lead to unauthorized access and significant security breaches if not addressed promptly. Users are urged to implement recommended patches and follow best practices to mitigate these risks.

Affected Version(s)

Common Licensing Agent 9.0

Common Licensing Agent 9.0.0.1

Common Licensing Agent 9.0.0.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.