Junglewise Threat Intelligence

CVE-2026-1029: IBM Common Licensing Agent cross-site scripting in Web UI

CVE-2026-1029 · Severity: medium · CVSS 5.4 · Published 2026-09-18

Technologies: IBM License Key Server Administration and Reporting Tool, IBM Common Licensing Agent. Vendors: IBM.

Executive brief

IBM Common Licensing Agent and related components display a web-based user interface for license management. An attacker can inject malicious JavaScript code into the interface that executes in a victim's trusted session, potentially stealing login credentials or modifying license settings. This affects multiple versions of the licensing administration tools.

Technical details

Cross-site scripting vulnerability (CWE-79) in the Web UI allows unauthenticated attackers to inject arbitrary JavaScript code via network requests. The vulnerability requires user interaction (UI:R) but affects the entire session and integrity context. Successful exploitation enables credential disclosure or manipulation of license data within the victim's authenticated browser session.

Affected products

  • IBM Common Licensing Agent 9.0, 9.0.0.1, 9.0.0.2
  • IBM License Key Server Administration and Reporting Tool 9.0, 9.0.0.1, 9.0.0.2
  • IBM LKS Administration Agent 9.0, 9.0.0.1, 9.0.0.2

Timeline

  • 2026-09-18: disclosed

References

Related threats