Race Condition in IBM Cognos Analytics 12.1.3 Agentic AI Report Failures
CVE-2026-15995 Published on July 17, 2026
IBM Cognos Analytics 12.1.3 general availability package contains a data integrity issue in the Agentic AI assistant that may cause incorrect report summaries or report-processing errors under concurrent use
IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results or cause report-processing failures due to a race condition in the Agentic AI assistant's concurrent request-handling logic when multiple authenticated users submit report-related tasks simultaneously.
Vulnerability Analysis
CVE-2026-15995 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is a Race Condition Vulnerability?
The program contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.
CVE-2026-15995 has been classified to as a Race Condition vulnerability or weakness.
Products Associated with CVE-2026-15995
Want to know whenever a new CVE is published for IBM Cognos Analytics? stack.watch will email you.
Affected Versions
IBM Cognos Analytics:- Version 12.1.3 GA Version with build number, <= 12.1.3-2606251736 is affected.