ZeroHour

CVE-2026-19646

Remote Open Redirect via Host Header Injection in IBM Common Licensing Agent and ART 9.0

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-19646 is an open redirect flaw in IBM Common Licensing Agent 9.0/9.0.0.1/9.0.0.2 and ART 9.0/9.0.0.1/9.0.0.2: the components fail to properly validate the HTTP Host header, so requests carrying a crafted Host value cause users to be redirected to an arbitrary attacker-chosen domain. A remote attacker who can send requests to the agent or ART web service — no privileges are required per the CVSS vector — can forge the Host header and land victims on a domain under their control, enabling phishing or interception of users who follow links through the service. IBM scored the issue 9.1 Critical (network vector, no privileges required, high confidentiality and integrity impact, no availability impact). Any organization running the affected Common Licensing Agent or ART releases is affected; these are license-serving components typically deployed on enterprise license servers, often on internal networks. No public proof-of-concept is known, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and there are no confirmed reports of exploitation in the wild.

What to do: Audit your environment for Common Licensing Agent or ART running versions 9.0, 9.0.0.1, or 9.0.0.2 and apply the fix referenced in IBM's security bulletin (no specific fixed version was listed in the bulletin summary). Until patched, restrict network access to the agent/ART web interface and enforce Host header validation (e.g., reverse-proxy normalization that only accepts expected hostnames). Be wary of links that pass through these services when assessing any phishing risk.

Affected
IBM Common Licensing Agent9.0, 9.0.0.1, 9.0.0.2
IBM ART (IBM Common Licensing component)9.0, 9.0.0.1, 9.0.0.2
Estimated exposure
unknown; plausibly on the order of only thousands of enterprise license-server deployments worldwide, mostly internal — no public install-base or… — IBM Common Licensing Agent/ART is a license-serving component typically installed on one to a few servers per customer environment and rarely exposed directly to the internet, and no public install-base statistics or scan data are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.

Weakness
CWE-1149
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.