CVE-2026-19646
Remote Open Redirect via Host Header Injection in IBM Common Licensing Agent and ART 9.0
CVE-2026-19646 is an open redirect flaw in IBM Common Licensing Agent 9.0/9.0.0.1/9.0.0.2 and ART 9.0/9.0.0.1/9.0.0.2: the components fail to properly validate the HTTP Host header, so requests carrying a crafted Host value cause users to be redirected to an arbitrary attacker-chosen domain. A remote attacker who can send requests to the agent or ART web service — no privileges are required per the CVSS vector — can forge the Host header and land victims on a domain under their control, enabling phishing or interception of users who follow links through the service. IBM scored the issue 9.1 Critical (network vector, no privileges required, high confidentiality and integrity impact, no availability impact). Any organization running the affected Common Licensing Agent or ART releases is affected; these are license-serving components typically deployed on enterprise license servers, often on internal networks. No public proof-of-concept is known, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and there are no confirmed reports of exploitation in the wild.
What to do: Audit your environment for Common Licensing Agent or ART running versions 9.0, 9.0.0.1, or 9.0.0.2 and apply the fix referenced in IBM's security bulletin (no specific fixed version was listed in the bulletin summary). Until patched, restrict network access to the agent/ART web interface and enforce Host header validation (e.g., reverse-proxy normalization that only accepts expected hostnames). Be wary of links that pass through these services when assessing any phishing risk.
| IBM Common Licensing Agent | 9.0, 9.0.0.1, 9.0.0.2 |
| IBM ART (IBM Common Licensing component) | 9.0, 9.0.0.1, 9.0.0.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.
- Weakness
- CWE-1149
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.