---
id: CVE-2026-19646
title: >-
  Multiple vulnerabilities affect IBM License Key Server Administration and
  Reporting Tool and IBM LKS Administration Agent
summary: >-
  IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART
  9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an
  arbitrary domain due to improper validation of the HTTP Host header.
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cvssSource: cna
cwe:
  - CWE-1149
vendor: IBM
product: Common Licensing
affected:
  - common_licensing Agent 9.0
  - common_licensing Agent 9.0.0.1
  - common_licensing Agent 9.0.0.2
  - common_licensing ART 9.0
  - common_licensing ART 9.0.0.1
  - common_licensing ART 9.0.0.2
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-11T17:02:47.722641Z'
published: '2026-09-10'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T17:04:13.786Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-19646'
references:
  - url: 'https://www.ibm.com/support/pages/node/7286490'
tags:
  - cve.org
epss: 0.0052
epssPercentile: 0.43186
ingestedAt: '2026-09-14T00:35:28.536Z'
---

## Overview

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.

## Affected

- `common_licensing Agent 9.0`
- `common_licensing Agent 9.0.0.1`
- `common_licensing Agent 9.0.0.2`
- `common_licensing ART 9.0`
- `common_licensing ART 9.0.0.1`
- `common_licensing ART 9.0.0.2`

## Remediation

Download and install IBM Common Licensing 9.1 from  Passport Advantage https://www.ibm.com/software/passportadvantage/pao-customer 



Users are strongly advised to update to the latest version (IBM Common Licensing 9.1) to mitigate any potential risks associated with these vulnerabilities.
