Cross-Site Scripting Vulnerability in IBM Common Licensing Agent and ART Software
CVE-2026-1031

6.1MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
18 September 2026

What is CVE-2026-1031?

IBM Common Licensing Agent and ART software versions 9.0, along with their specific agent releases, are vulnerable to a cross-site scripting flaw. This security issue enables an unauthenticated attacker to inject arbitrary JavaScript into the Web UI, potentially compromising the intended functionality of the application. This manipulation can open pathways for credential disclosure during trusted sessions, posing significant security risks to users.

Affected Version(s)

Common Licensing Agent 9.0

Common Licensing Agent 9.0.0.1

Common Licensing Agent 9.0.0.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.