CVE-2026-19646
Received
Received - Intake
IBM Common Licensing Agent HTTP Host Header Redirect Vulnerability
Vulnerability report for CVE-2026-19646, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-10
Last updated on: 2026-09-10
Assigner: IBM Corporation
Description
Description
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | common_licensing_agent | 9.0 |
| ibm | common_licensing_agent | 9.0.0.1 |
| ibm | common_licensing_agent | 9.0.0.2 |
| ibm | art | 9.0 |
| ibm | art | 9.0.0.1 |
| ibm | art | 9.0.0.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1149 |