CVE-2025-36076
IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.
- Published Sep 18, 2026
- CVSS 4.3 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- Multiple vulnerabilities in IBM products CERT-FR ·