Vulnerability Intelligence Report
Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent
CVE-2026-19543
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values, potentially resulting in unintended application behavior.
No Active Exploit Signals
CVSS Base Score
6.2
MEDIUM
Exploitability:2.6
Impact Score:3.6
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-20 ↗CWE-20 Improper Input Validation
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| IBM | Common Licensing | Agent 9.0 (affected), Agent 9.0.0.1 (affected), Agent 9.0.0.2 (affected), ART 9.0 (affected), ART 9.0.0.1 (affected), ART 9.0.0.2 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | IBM Corporation · Vendor · USA |
| Reserved | 2026-08-11T13:01:37 |
| Published | 2026-09-14T18:26:13 |
| Last Updated | 2026-09-14T19:22:58 |
Community Chatter & Buzz