CVE-2025-36126: IBM Cognos Analytics

High severity, CVSS 7.6. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Affected products

  • IBM Cognos Analytics: from 12.1.0, before 12.1.2 (fixed in 12.1.2); version 11.2 only; version 11.2.0 only; version 11.2.1 only; version 11.2.2 only; version 11.2.3 only; …
  • IBM Cognos Transformer: version 11.2.4 only; version 12.0 only; version 12.1.0 only

Published 2026-05-26. Last modified 2026-07-24.