CVE-2025-36076

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.

  • Published Sep 18, 2026
  • CVSS 4.3 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2025-36076 at the National Vulnerability Database