← Back to search

CVE-2025-15399

10 CRITICAL

Published 2026-09-18 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows an attacker to execute unauthorized actions by tricking a user into performing a request on a website they trust, potentially leading to data theft, system compromise, and unauthorized access.
Exploitability
Exploitation is relatively easy as it requires an attacker to craft a malicious request that the user's browser will execute without their knowledge. Precondition is that the user is already logged into the affected website.
Blast radius
If exploited, the impact could be severe, including data exfiltration, system compromise, and unauthorized access to sensitive information.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected Common Licensing Agent and ART features or upgrade to IBM Common Licensing Agent 9.0.0.3 or later.
csrfwebauth-bypasscross-sitelicensing

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-352

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.