Description
IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results or cause report-processing failures due to a race condition in the Agentic AI assistant's concurrent request-handling logic when multiple authenticated users submit report-related tasks simultaneously.
Published: 2026-07-17
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Cognos Analytics 12.1.3 is affected by a race condition in the Agentic AI assistant that can corrupt report summary data or trigger report-processing errors. The flaw exists because concurrent requests from authenticated users are not properly synchronized, resulting in data integrity failures and denial of service for analytical reporting, indicating a basic concurrency issue.

Affected Systems

All installations of IBM Cognos Analytics version 12.1.3 that have not yet been upgraded to build 12.1.3-2607110822 are vulnerable. The vulnerability is present in the GA package through build number 12.1.3-2606251736, as identified by the CPE strings and the IBM advisory. Customers running a 12.1.3 release must check their build version and apply the corrected package.

Risk and Exploitability

The CVSS score of 5.4 classifies the issue as moderate severity, and the EPSS score of less than 1% shows that the probability of exploitation is low. Because the flaw requires an authenticated user to create concurrent report tasks users already logged into Cognos. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread, active exploitation has been reported. Nonetheless, deploying the available fix will eliminate the risk of incorrect data or processing failures under concurrent usage.

Generated by OpenCVE AI on July 30, 2026 at 23:41 UTC.

Remediation

Vendor Solution

IBM has addressed this issue in an updated Cognos Analytics 12.1.3 package available from Passport Advantage released on July 16th. The build number of the corrected release is 12.1.3-2607110822.  Customers should obtain and deploy the updated package to remediate the issue. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Cognos Analytics12.1.3 updated with build number 12.1.3-2607110822  IBM Cognos Analytics 12.1.3 https://www.ibm.com/software/passportadvantage/pao-customer


OpenCVE Recommended Actions

  • Obtain the updated Cognos Analytics 12.1.3 package build 12.1.3-2607110822 from IBM Passport Advantage and replace the current installation.
  • Deploy the updated package to every Cognos server in the environment, ensuring the upgrade is applied consistently across the cluster.
  • After deployment, run concurrent report generation tests to confirm that summary results are correct and no processing errors occur.

Generated by OpenCVE AI on July 30, 2026 at 23:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results or cause report-processing failures due to a race condition in the Agentic AI assistant's concurrent request-handling logic when multiple authenticated users submit report-related tasks simultaneously.
Title IBM Cognos Analytics 12.1.3 general availability package contains a data integrity issue in the Agentic AI assistant that may cause incorrect report summaries or report-processing errors under concurrent use
First Time appeared Ibm
Ibm cognos Analytics
Weaknesses CWE-362
CPEs cpe:2.3:a:ibm:cognos_analytics:12.1.3-2606251736:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.1.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cognos Analytics
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Cognos Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-20T13:28:31.747Z

Reserved: 2026-07-16T21:12:15.436Z

Link: CVE-2026-15995

cve-icon Vulnrichment

Updated: 2026-07-20T13:28:27.431Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:45:05Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')