CVE-2026-19646: Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.
Other sources
IBM Common Licensing could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Common Licensingto a version that resolves this vulnerability.Fixed in 9.1
Event History
Frequently Asked Questions
Which deployments should be prioritized for review?
Inventory IBM Common Licensing Agent 9.0, 9.0.0.1, and 9.0.0.2, along with ART 9.0, 9.0.0.1, and 9.0.0.2. These releases are identified as affected.
Does an attacker need credentials or user interaction to exploit this?
No. The CVSS vector indicates network access, low attack complexity, no privileges required, and no user interaction required.
What is the expected security impact?
The issue can be used to redirect users to an arbitrary domain. The supplied CVSS metrics rate confidentiality and integrity impact as high, with no availability impact.