Description
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Published: 2026-09-18
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Execution of unauthorized web actions via CSRF
Action: Patch Immediately
AI Analysis

Impact

IBM Common Licensing Agent and ART modules are vulnerable to a cross‑site request forgery flaw. The flaw permits an attacker who tricks a trusted user into submitting a forged request to the web interface to carry out actions that the victim’s account would normally allow. Because the flaw operates through a web endpoint that requires authentication, the attacker can execute operations on the server without needing local or privileged access.

Affected Systems

Affected releases are IBM Common Licensing Agent versions 9.0, 9.0.0.1 and 9.0.0.2 and ART 9.0, 9.0.0.1 and 9.0.0.2. All of those components are distributed under the IBM Common Licensing umbrella. The vendor recommendation is to upgrade to IBM Common Licensing 9.1, which contains the fix.

Risk and Exploitability

The CVSS score of 10 classifies the vulnerability as critical. EPSS is listed as <1%, indicating a very low predicted exploitation probability, and the issue is not currently in the CISA KEV catalog. The attack path requires the victim to be authenticated against the web interface; an attacker can then lure the victim to click a malicious link or load a page that sends a forged request. Because the vulnerability does not need direct server access, exploiting it can be performed remotely from a web browser, but a malicious request must target a system where the victim is logged in.

Generated by OpenCVE AI on September 19, 2026 at 18:26 UTC.

Remediation

Vendor Solution

Download and install IBM Common Licensing 9.1 from Passport Advantage https://www.ibm.com/software/passportadvantage/pao-customer Users are strongly advised to update to the latest version (IBM Common Licensing 9.1) to mitigate any potential risks associated with these vulnerabilities.


OpenCVE Recommended Actions

  • Download and install IBM Common Licensing 9.1 from Passport Advantage
  • Restrict web access to the licensing server to trusted networks or enforce multifactor authentication for administrative endpoints
  • Verify that CSRF token validation is enabled and not bypassed by custom middleware

Generated by OpenCVE AI on September 19, 2026 at 18:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Title Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent
First Time appeared Ibm
Ibm common Licensing
Weaknesses CWE-352
CPEs cpe:2.3:a:ibm:common_licensing:agent:*:*:*:*:*:*:*
cpe:2.3:a:ibm:common_licensing:art:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm common Licensing
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Common Licensing
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-21T12:47:24.017Z

Reserved: 2025-12-31T14:56:30.484Z

Link: CVE-2025-15399

cve-icon Vulnrichment

Updated: 2026-09-21T12:45:13.914Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:02.387

Modified: 2026-09-21T13:17:06.053

Link: CVE-2025-15399

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:30:16Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)