IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1

Published September 10, 2026 CVE-2026-19646

IBM Common Licensing can redirect users to an attacker-chosen website. The affected versions are Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2.

Severity
CriticalCVSS 3.1 · 9.1
Fix
Not confirmedLast checked today
Affected versions
Agent 9.0; Agent 9.0.0.1; Agent 9.0.0.2+3 more
Weakness
CWE-1149
Exploit likelihood
0.52% in 30 daysEPSS, higher than 43% of known flaws
Affects
Common Licensing
Exploited
Not confirmedNo confirmation recorded
CISA SSVC
No known exploitationAutomatable: yes · Technical impact: total
EU ID
EUVD-2026-75877ENISA vulnerability database

How it works

  • IBM Common Licensing does not properly validate the HTTP Host header.
  • That can allow a remote attacker to redirect users to an arbitrary domain.
  • The supplied advisory does not describe the exact request sequence that triggers the redirect.

What to do

Compare your IBM Common Licensing installation with the affected Agent and ART versions listed in the IBM advisory.

Install IBM Common Licensing 9.1 through IBM Passport Advantage. Follow the IBM security bulletin for the documented remediation.

Technical details

CVE-2026-19646 concerns improper validation of the HTTP Host header in IBM Common Licensing. The issue can redirect users to an arbitrary domain without requiring login or user interaction.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact None No availability impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Open in FIRST.org calculator

References