Input Validation Flaw in IBM Common Licensing Agent and ART Products
CVE-2026-19543

6.2MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
14 September 2026

What is CVE-2026-19543?

The IBM Common Licensing Agent and ART products experience a significant security flaw due to client-side input validation that is not enforced server-side. This weakness allows attackers to manipulate requests and bypass essential validation checks, leading to unauthorized submissions and unpredictable application behavior. Organizations using these products are recommended to review and patch their systems promptly to mitigate potential exploitation risks.

Affected Version(s)

Common Licensing Agent 9.0

Common Licensing Agent 9.0.0.1

Common Licensing Agent 9.0.0.2

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.