boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-15995MEDIUM
IBM Cognos Analytics 12.1.3 general availability package contains a data integrity issue in the Agentic AI assistant that may cause incorrect report summaries or report-processing errors under concurrent use
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  U  L  L  N    4.2   .0010    1.0     —
AFFECTED
  Product           Versions                               Fixed
  Cognos Analytics  12.1.3 GA Version with build number –  —
TIMELINE
  Jul 16  Reserved by ibm
  Jul 17  Published (CNA: ibm)
  Aug 11  RESCORED — CVE-2026-15995 (IBM Cognos Analytics). CVSS 5.4 → 4.2 (NVD).
CWE-362 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed

Description

IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results or cause report-processing failures due to a race condition in the Agentic AI assistant's concurrent request-handling logic when multiple authenticated users submit report-related tasks simultaneously.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
July 16, 2026ReservedReserved by ibm
July 17, 2026PublishedPublished (CNA: ibm)
August 11, 2026RESCOREDRESCORED — CVE-2026-15995 (IBM Cognos Analytics). CVSS 5.4 → 4.2 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
IBMCognos Analytics12.1.3 GA Version with build number

Weaknesses

CWE-362

References (1)

Related

Authoritative record: CVE-2026-15995 at cve.org

Vendors: ibm

Weaknesses: CWE-362

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-15995 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.