{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-19543","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2026-08-11T13:01:37.058Z","datePublished":"2026-09-14T18:26:13.674Z","dateUpdated":"2026-09-14T19:22:58.899Z"},"containers":{"cna":{"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2026-09-14T18:26:13.674Z"},"title":"Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-20","description":"CWE-20 Improper Input Validation","type":"CWE"}]}],"affected":[{"vendor":"IBM","product":"Common Licensing","versions":[{"status":"affected","version":"Agent 9.0"},{"status":"affected","version":"Agent 9.0.0.1"},{"status":"affected","version":"Agent 9.0.0.2"},{"status":"affected","version":"ART 9.0"},{"status":"affected","version":"ART 9.0.0.1"},{"status":"affected","version":"ART 9.0.0.2"}],"cpes":["cpe:2.3:a:ibm:common_licensing:agent:*:*:*:*:*:*:*","cpe:2.3:a:ibm:common_licensing:art:*:*:*:*:*:*:*"]}],"descriptions":[{"lang":"en","value":"IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values, potentially resulting in unintended application behavior.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values, potentially resulting in unintended application behavior.</p>"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286490","tags":["vendor-advisory","patch"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseSeverity":"MEDIUM","baseScore":6.2,"vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}}],"solutions":[{"lang":"en","value":"Download and install IBM Common Licensing 9.1 from  Passport Advantage https://www.ibm.com/software/passportadvantage/pao-customer \n\n\n\nUsers are strongly advised to update to the latest version (IBM Common Licensing 9.1) to mitigate any potential risks associated with these vulnerabilities.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>Download and install IBM Common Licensing 9.1 from <a href=\"https://www.ibm.com/software/passportadvantage/pao-customer\" rel=\"nofollow\">Passport Advantage</a></p><p>Users are strongly advised to update to the latest version (IBM Common Licensing 9.1) to mitigate any potential risks associated with these vulnerabilities.</p>"}]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2026-19543","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2026-09-14T19:10:12.791300Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-14T19:22:58.899Z"}}]}}