Cross-Site Scripting Vulnerability in IBM Common Licensing Agent and ART
CVE-2026-1037

6.1MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
18 September 2026

What is CVE-2026-1037?

The IBM Common Licensing Agent and ART products are susceptible to a cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript code into the web user interface. This exploitation can modify the intended functionality of the web application, posing significant risks including the potential for credential disclosure during trusted sessions. It is crucial for users of these affected IBM products to apply the necessary security patches to prevent possible attacks.

Affected Version(s)

Common Licensing Agent 9.0

Common Licensing Agent 9.0.0.1

Common Licensing Agent 9.0.0.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.