IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1
IBM Common Licensing can redirect users to an attacker-chosen website. The affected versions are Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2.
- Severity
- CriticalCVSS 3.1 · 9.1
- Fix
- Not confirmedLast checked today
- Affected versions
- Agent 9.0; Agent 9.0.0.1; Agent 9.0.0.2+3 more
- Weakness
- CWE-1149
- Exploit likelihood
- 0.52% in 30 daysEPSS, higher than 43% of known flaws
- Affects
- Common Licensing
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: yes · Technical impact: total
- EU ID
- EUVD-2026-75877ENISA vulnerability database
How it works
- IBM Common Licensing does not properly validate the HTTP Host header.
- That can allow a remote attacker to redirect users to an arbitrary domain.
- The supplied advisory does not describe the exact request sequence that triggers the redirect.
What to do
Compare your IBM Common Licensing installation with the affected Agent and ART versions listed in the IBM advisory.
Install IBM Common Licensing 9.1 through IBM Passport Advantage. Follow the IBM security bulletin for the documented remediation.
Technical details
CVE-2026-19646 concerns improper validation of the HTTP Host header in IBM Common Licensing. The issue can redirect users to an arbitrary domain without requiring login or user interaction.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact None No availability impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Open in FIRST.org calculatorReferences
- ibm.com · 7286490 vendor-advisory patch NVD
- cve.org · CVERecord vdb entry
- tenable.com · CVE-2026-19646 third party advisory vdb entry
- cvefeed.io · CVE-2026-19646 third party advisory vdb entry
- cveawg.mitre.org · CVE-2026-19646