CVE-2026-7884

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include malicious JavaScript code. When an administrator later accesses the user account management panel and views that user's permissions, the malicious JavaScript code is executed. This could result in the cookies from the administrator being compromised.

Scoring

Severity
MEDIUM
CVSS base score
5.4
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS probability
0.23%
CWE
CWE-79
Published
2026-09-14
Last modified
2026-09-15

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs