CVE-2026-1025: IBM Common Licensing vulnerability
Published Sep 7, 2026
·Updated
IBM Common Licesning is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
6 affected components
IBM Common Licensing<=Agent 9.0
IBM Common Licensing<=Agent 9.0.0.1
IBM Common Licensing<=Agent 9.0.0.2
IBM Common Licensing<=ART 9.0
IBM Common Licensing<=ART 9.0.0.1
IBM Common Licensing<=ART 9.0.0.2
Event History
Sep 7, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker needs the ability to embed arbitrary JavaScript code in the IBM Common Licensing Web UI. The provided information does not state which input, role, or access level permits that action.
2
What is the likely impact on users?
Malicious JavaScript can alter intended Web UI functionality and may lead to credential disclosure within a trusted user session.