CVE-2026-15995: IBM Cognos Analytics 12.1.3 general availability package contains a data integrity issue in the Agentic AI assistant that may cause incorrect report summaries or report-processing errors under concurrent use
IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results or cause report-processing failures due to a race condition in the Agentic AI assistant's concurrent request-handling logic when multiple authenticated users submit report-related tasks simultaneously.
Other sources
IBM Cognos Analytics could allow an attacker to obtain incorrect report summary results or cause report-processing failures due to a race condition in the Agentic AI assistant's concurrent request-handling logic when multiple authenticated users submit report-related tasks simultaneously.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Cognos Analytics 12.1.3to a version that resolves this vulnerability.Fixed in 12.1.3-2607110822
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15995?
The severity of CVE-2026-15995 is categorized as medium with a score of 5.4.
What impact does CVE-2026-15995 have on IBM Cognos Analytics?
CVE-2026-15995 can cause incorrect report summaries and report-processing errors when multiple requests are handled concurrently.
How do I fix CVE-2026-15995?
To address CVE-2026-15995, update IBM Cognos Analytics to a version that resolves the race condition issue in the Agentic AI assistant.
Who is affected by CVE-2026-15995?
CVE-2026-15995 affects users of IBM Cognos Analytics version 12.1.3 with build number through 12.1.3-2606251736.
What is the main cause of CVE-2026-15995?
The main cause of CVE-2026-15995 is a race condition in the concurrent request-handling logic of the Agentic AI assistant.