Description
IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published: 2026-05-26
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Cognos Analytics and Cognos Transformer versions 11.2.0, 12.0, and 12.1.0 contain a stored cross‑site scripting flaw in the administration interface. A user with privileged administrative rights can embed arbitrary JavaScript into the web UI. When other users view the affected pages, the injected code runs in their browsers, potentially exposing login credentials or other sensitive data from the trusted session. The weakness is identified as CWE‑79, a classic reflected or stored XSS vulnerability.

Affected Systems

Affected product families are IBM Cognos Analytics and IBM Cognos Transformer. The problem exists in Cognos Analytics 11.2.0 through 11.2.4 (up to Fix Pack 6), Cognos Analytics 12.0.0 through 12.0.4 (up to Fix Pack 1), and Cognos Analytics 12.1.0 through 12.1.2 (up to Fix Pack 2). The Cognos Transformer versions 11.2.4, 12.0.0, and 12.1.0 are also impacted. Each product line has a documented fix pack that removes the vulnerability, and users should upgrade to the latest available fix pack per vendor guidance.

Risk and Exploitability

The CVSS score of 6.4 indicates the vulnerability is moderate in severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog, suggesting it is not yet exploited in the wild. However, because the exploit requires a privileged administrator in the Cognos platform, once an attacker gains that access they can persist malicious scripts that run for all users and potentially compromise credentials. The risk is chiefly an insider threat or an attacker who has already stolen privileged credentials, so organizations should treat it as a moderate to high risk.

Generated by OpenCVE AI on May 26, 2026 at 18:27 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading to latest versions Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Cognos Analytics11.2.0 - 11.2.4 FP6 IBM Cognos Analytics 11.2.4 Fix Pack 7 https://www.ibm.com/support/pages/node/7270262 IBM Cognos Analytics12.0.0 - 12.0.4 FP1 IBM Cognos Analytics 12.0.4 Fix Pack 2 https://www.ibm.com/support/pages/node/7269268 IBM Cognos Analytics12.1.0 - 12.1.1 IF1 IBM Cognos Analytics 12.1.2 https://www.ibm.com/support/pages/node/7258071


OpenCVE Recommended Actions

  • Update all Cognos Analytics and Cognos Transformer installations to the latest fix packs (11.2.4 Fix Pack 7, 12.0.4 Fix Pack 2, and 12.1.2).
  • Restrict access to the Cognos Administration console to only trusted, audited users and review permissions to ensure only authorized personnel can add or edit frames that may contain script code.
  • Remove any existing stored JavaScript sections in the administrative pages and verify that no unintended scripts are present before allowing normal user access.

Generated by OpenCVE AI on May 26, 2026 at 18:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 17:00:00 +0000

Type Values Removed Values Added
Description IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM Cognos Analytics is affected by multiple security vulnerabilities
First Time appeared Ibm
Ibm cognos Analytics
Ibm cognos Transformer
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:cognos_analytics:11.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_transformer:11.2.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_transformer:12.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_transformer:12.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_transformer:12.1.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cognos Analytics
Ibm cognos Transformer
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Ibm Cognos Analytics Cognos Transformer
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-05-26T15:52:49.002Z

Reserved: 2025-04-15T21:16:18.171Z

Link: CVE-2025-36126

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-26T17:16:28.713

Modified: 2026-05-26T19:06:14.330

Link: CVE-2025-36126

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T18:30:12Z

Weaknesses