SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-19543

MEDIUM · CVSS 6.2 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM Common Licensing Agent and ART versions 9.0 and specific subversions are vulnerable due to inadequate server-side input validation, relying solely on client-side checks. This flaw allows attackers to manipulate requests, potentially leading to unauthorized actions and unpredictable application behavior. Organizations using these products should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-19543
Severity
MEDIUM
CVSS
6.2
EPSS
0.17%

Original NVD Description

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values, potentially resulting in unintended application behavior.