Junglewise Threat Intelligence

CVE-2026-7884: IBM Cognos Analytics stored cross-site scripting in user profile

CVE-2026-7884 · Severity: medium · CVSS 5.4 · Published 2026-09-14

Technologies: IBM Cognos Analytics. Vendors: IBM.

Executive brief

IBM Cognos Analytics is a business intelligence and analytics platform used by organizations to analyze and visualize data. A vulnerability allows non-privileged users to inject malicious JavaScript code into their user profile (given name and surname fields). When an administrator accesses the user account management panel to review permissions, the injected code executes with the administrator's privileges, potentially allowing attackers to steal administrative session cookies and gain unauthorized access to the system.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in IBM Cognos Analytics' user profile management. The vulnerability exists because user-supplied input in the given name and surname fields is not properly sanitized or escaped when displayed in the user account management panel. An unauthenticated attacker can inject JavaScript code through these profile fields; when an administrator later views the user's permissions, the malicious script executes in the administrator's browser context. This allows the attacker to steal administrative session cookies or perform other actions with administrator privileges. The vulnerability affects Cognos Analytics versions 12.0.4 through 12.0.4 FP2 and 12.1.0 through 12.1.3 FP1. Patches are expected to be available from IBM.

Affected products

  • IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1

Timeline

  • 2026-09-14: disclosed

References

Related threats