CVE-2026-15995: IBM Cognos Analytics

Medium severity, CVSS 4.2. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results or cause report-processing failures due to a race condition in the Agentic AI assistant's concurrent request-handling logic when multiple authenticated users submit report-related tasks simultaneously.

Affected products

  • IBM Cognos Analytics: version 12.1.3 only

Published 2026-07-17. Last modified 2026-08-11.