CVE-2026-19543: Input Validation
Published Sep 7, 2026
·Updated
IBM Common Licensing performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values, potentially resulting in unintended application behavior.
Affected Software
6 affected components
IBM Common Licensing<=Agent 9.0
IBM Common Licensing<=Agent 9.0.0.1
IBM Common Licensing<=Agent 9.0.0.2
IBM Common Licensing<=ART 9.0
IBM Common Licensing<=ART 9.0.0.1
IBM Common Licensing<=ART 9.0.0.2
Event History
Sep 7, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What capability does an attacker need to exploit this issue?
The attacker needs to be able to modify requests sent to IBM Common Licensing. By altering client-submitted values, they may bypass validation controls that are not enforced by the server.
2
Which deployments are potentially exposed?
Deployments are potentially exposed where IBM Common Licensing accepts values subject only to client-side validation. The provided information does not identify affected versions, configurations, or whether any default deployment is affected.