Stored Cross-Site Scripting in IBM Cognos Analytics and Transformer
CVE-2025-36126

6.4MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
26 May 2026

What is CVE-2025-36126?

IBM Cognos Analytics and Cognos Transformer are affected by a stored cross-site scripting vulnerability that enables privileged users to inject arbitrary JavaScript code into the web user interface. This injection can potentially alter the intended functionality of the application, leading to exposure of sensitive information such as user credentials during a trusted session. Prompt attention is advised to mitigate the risks associated with this vulnerability.

Affected Version(s)

Cognos Analytics 11.2.0 <= 3.2.4.15

Cognos Analytics 12.0

Cognos Analytics 12.1.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.