Junglewise Threat Intelligence

CVE-2026-1025: IBM Common Licensing Agent cross-site scripting in Web UI

CVE-2026-1025 · Severity: medium · CVSS 6.1 · Published 2026-09-18

Technologies: IBM License Key Server Administration and Reporting Tool, IBM Common Licensing Agent. Vendors: IBM.

Executive brief

IBM Common Licensing Agent is a license management tool used by enterprises to track and administer software licensing. The vulnerability allows an attacker to inject arbitrary JavaScript code into the Web UI, potentially stealing user credentials or hijacking administrative sessions through malicious web content.

Technical details

Cross-site scripting (CWE-79) in the Web UI allows unauthenticated attackers to inject arbitrary JavaScript that executes in the context of a user's trusted session. The vulnerability requires user interaction (clicking a malicious link) but has a network attack vector with no privilege requirements. A successful exploit can disclose session credentials or modify application behavior.

Affected products

  • IBM Common Licensing Agent 9.0, 9.0.0.1, 9.0.0.2
  • IBM License Key Server Administration and Reporting Tool 9.0, 9.0.0.1, 9.0.0.2

Timeline

  • 2026-09-18: disclosed

References

Related threats