Junglewise Threat Intelligence

CVE-2026-1031: IBM Common Licensing Agent cross-site scripting in Web UI

CVE-2026-1031 · Severity: medium · CVSS 6.1 · Published 2026-09-18

Technologies: IBM License Key Server Administration and Reporting Tool, IBM Common Licensing Agent. Vendors: IBM.

Executive brief

IBM Common Licensing Agent is a license management tool used to administer and report on software licensing. An unauthenticated attacker can inject malicious JavaScript code into the Web UI, allowing credential theft or unauthorized actions within trusted user sessions. This could lead to the compromise of license administrator accounts and sensitive licensing data.

Technical details

A stored or reflected cross-site scripting (XSS) vulnerability in the Web UI component fails to sanitize user input, allowing unauthenticated attackers to inject arbitrary JavaScript. The attack requires user interaction (clicking a malicious link) but affects an unauthenticated threat model. Successful exploitation enables session hijacking, credential disclosure, and privilege escalation within the context of an authenticated user's session.

Affected products

  • IBM Common Licensing Agent 9.0, 9.0.0.1, 9.0.0.2
  • IBM License Key Server Administration and Reporting Tool 9.0, 9.0.0.1, 9.0.0.2

Timeline

  • 2026-09-18: disclosed

References

Related threats