Improper Validation Vulnerability in IBM Common Licensing Agent and ART
CVE-2026-19646
9.1CRITICAL
What is CVE-2026-19646?
An improper validation vulnerability exists in the IBM Common Licensing Agent and IBM ART that may allow attackers to redirect legitimate users to an arbitrary domain. This occurs due to insufficient checks on the HTTP Host header, which could lead to user data exposure or further compromise if exploited. It is crucial for users of the affected versions to apply the relevant patches and strengthen protection measures.
Affected Version(s)
Common Licensing Agent 9.0
Common Licensing Agent 9.0.0.1
Common Licensing Agent 9.0.0.2