---
id: CVE-2026-19543
title: >-
  IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART
  9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client
  side and fails to enforce the same restrictions on the server side
summary: >-
  IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART
  9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client
  side and fails to enforce the same restrictions on the server side. An
  attacker can m…
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-20
vendor: IBM
product: Common Licensing
affected:
  - common_licensing Agent 9.0
  - common_licensing Agent 9.0.0.1
  - common_licensing Agent 9.0.0.2
  - common_licensing ART 9.0
  - common_licensing ART 9.0.0.1
  - common_licensing ART 9.0.0.2
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:22:22.797'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19543'
references:
  - url: 'https://www.ibm.com/support/pages/node/7286490'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
epss: 0.0012
epssPercentile: 0.0162
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T19:10:12.791300Z'
ingestedAt: '2026-09-14T19:13:23.472Z'
---

## Overview

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values, potentially resulting in unintended application behavior.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
