{"id":"CVE-2026-19543","title":"IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side","summary":"IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can m…","severity":"medium","cvss":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-20"],"vendor":"IBM","product":"Common Licensing","affected":["common_licensing Agent 9.0","common_licensing Agent 9.0.0.1","common_licensing Agent 9.0.0.2","common_licensing ART 9.0","common_licensing ART 9.0.0.1","common_licensing ART 9.0.0.2"],"published":"2026-09-14","updated":"2026-09-16","sourceUpdated":"2026-09-16T19:22:22.797","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19543","references":[{"url":"https://www.ibm.com/support/pages/node/7286490","label":"psirt@us.ibm.com"}],"tags":["nvd","cve.org"],"epss":0.0012,"epssPercentile":0.01614,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T19:10:12.791300Z"},"ingestedAt":"2026-09-14T19:13:23.472Z","slug":"CVE-2026-19543","body":"## Overview\n\nIBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values, potentially resulting in unintended application behavior.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":34.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}