MEDIUM

CVE-2026-19543

2026-09-14 CVSS v3.1
CVSS
6.2

Description

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values, potentially resulting in unintended application behavior.

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

0.17%
Probability of exploitation in next 30 days
6.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE