JavaScript Injection Vulnerability in IBM Cognos Analytics
CVE-2026-7884

5.4MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
14 September 2026

What is CVE-2026-7884?

A vulnerability in IBM Cognos Analytics versions 12.1.0 through 12.1.3 FP1 and 12.0.4 through 12.0.4 FP2 allows non-privileged users to manipulate their profile names with malicious JavaScript code. When administrators view user permissions, the embedded code is executed, potentially compromising sensitive session cookies. This vulnerability highlights the need for robust input validation and access control measures in user management functionalities.

Affected Version(s)

Cognos Analytics 12.1.0 <= 12.1.3 FP1

Cognos Analytics 12.0.4 <= 12.0.4 FP2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.