Improper Validation Vulnerability in IBM Common Licensing Agent and ART
CVE-2026-19646

9.1CRITICAL

Key Information:

Vendor

IBM

Vendor
CVE Published:
10 September 2026

What is CVE-2026-19646?

An improper validation vulnerability exists in the IBM Common Licensing Agent and IBM ART that may allow attackers to redirect legitimate users to an arbitrary domain. This occurs due to insufficient checks on the HTTP Host header, which could lead to user data exposure or further compromise if exploited. It is crucial for users of the affected versions to apply the relevant patches and strengthen protection measures.

Affected Version(s)

Common Licensing Agent 9.0

Common Licensing Agent 9.0.0.1

Common Licensing Agent 9.0.0.2

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.