Executive brief
IBM Cognos Analytics and Transformer, which are used for business intelligence and data modeling, are affected by a security flaw in their administration interface. A user with basic privileges could inject malicious scripts into the web interface that would then run in the browsers of other users. This could allow an attacker to steal login credentials or perform unauthorized actions within the application.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Cognos Administration component of IBM Cognos Analytics and Cognos Transformer. The flaw allows a remote authenticated user with certain privileges to inject malicious JavaScript code into the application's web interface. Because the script is stored, it executes in the context of any user who subsequently views the affected page. This can lead to the disclosure of sensitive information, such as session credentials, or the alteration of intended web functionality. The vulnerability is tracked as CVE-2025-36126 and has a CVSS base score of 6.4.
Affected products
- IBM Cognos Analytics 11.2.0, 12.0, 12.1.0
- IBM Cognos Transformer 11.2.4, 12.0, 12.1.0
Timeline
- 2026-05-26: disclosed
- 2026-05-26: advisory