CVE-2026-19543
Received
Received - Intake
IBM Common Licensing Agent Server-Side Input Validation Bypass
Vulnerability report for CVE-2026-19543, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-14
Last updated on: 2026-09-14
Assigner: IBM Corporation
Description
Description
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values, potentially resulting in unintended application behavior.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | common_licensing_agent | 9.0 |
| ibm | common_licensing_agent | 9.0.0.1 |
| ibm | common_licensing_agent | 9.0.0.2 |
| ibm | art | 9.0 |
| ibm | art | 9.0.0.1 |
| ibm | art | 9.0.0.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-20 | The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. |