CVE-2026-7884
Received Received - Intake

Stored XSS in IBM Cognos Analytics User Profile

Vulnerability report for CVE-2026-7884, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: IBM Corporation

Description

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include malicious JavaScript code. When an administrator later accesses the user account management panel and views that user's permissions, the malicious JavaScript code is executed. This could result in the cookies from the administrator being compromised.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ibm cognos_analytics From 12.1.0 (inc) to 12.1.3 (inc)
ibm cognos_analytics 12.0.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Cognos Analytics versions 12.1.0 through 12.1.3 FP1 and 12.0.4 through 12.0.4 FP2 have a vulnerability where a non-privileged user can inject malicious JavaScript code into their given name and surname fields. When an administrator views the user's permissions, the JavaScript executes, potentially compromising the administrator's cookies.

Impact Analysis

If you are an administrator using IBM Cognos Analytics in the affected versions, this vulnerability could allow attackers to steal your session cookies or perform actions on your behalf by executing malicious JavaScript when you view user permissions.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR's data protection requirements or HIPAA's security rules for protected health information. Organizations using affected versions may face compliance risks due to potential data breaches.

Mitigation Strategies

Update IBM Cognos Analytics to a version that patches this vulnerability. Remove any malicious JavaScript code from user given names and surnames. Restrict user permissions to prevent unauthorized modifications. Monitor administrator access to user accounts for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-7884. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart