← Back to CVE List
Vulnerability Intelligence Report
Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent

CVE-2026-19543

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values, potentially resulting in unintended application behavior.

No Active Exploit Signals
CVSS Base Score
6.2
MEDIUM
Exploitability:2.6
Impact Score:3.6
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-20 ↗CWE-20 Improper Input Validation

Affected Products & Versions

Vendor Product Affected Versions
IBM Common Licensing Agent 9.0 (affected), Agent 9.0.0.1 (affected), Agent 9.0.0.2 (affected), ART 9.0 (affected), ART 9.0.0.1 (affected), ART 9.0.0.2 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityIBM Corporation · Vendor · USA
Reserved2026-08-11T13:01:37
Published2026-09-14T18:26:13
Last Updated2026-09-14T19:22:58

LINK COPIED TO CLIPBOARD