Executive brief
IBM Cognos Analytics is a business intelligence platform used for data reporting and analysis. A flaw in its AI assistant component could allow authenticated users to inadvertently receive incorrect report data or cause system errors when multiple people run reports at the same time. This issue impacts data integrity and the reliability of business reports, though it requires the attacker to have valid login credentials.
Technical details
A race condition (CWE-362) exists in the Agentic AI assistant's concurrent request-handling logic within IBM Cognos Analytics. The vulnerability is triggered when multiple authenticated users submit report-related tasks or queries simultaneously through the user interface. An attacker with low-privileged network access can exploit this improper synchronization of shared resources to cause data integrity issues (incorrect report summaries) or a partial denial of service (processing failures). IBM has released an updated package (build 12.1.3-2607110822) to remediate the issue.
Affected products
- IBM Cognos Analytics 12.1.3 GA through build 12.1.3-2606251736
Timeline
- 2026-07-16: patched: Updated package released on Passport Advantage
- 2026-07-17: disclosed: Initial advisory publication