← Vulnerability feed

Vulnerability record · CVE-2025-36326 · published 26 September 2025

CVE-2025-36326: Ibm cognos controller vulnerability

Ibm · Cognos Controller

IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to the use of hardcoded cryptographic keys for signing session cookies.

7.5 CVSS 3.1 High EPSS 0.23% · top 87.7% CWE-321 · CWE-321
7.5CVSS 3.1 base score
0.23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to the use of hardcoded cryptographic keys for signing session cookies.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-36326 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-25020Ibm cognos controller unrestricted file upload vulnerabilityIBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Journal entry pag…EPSS 0.28%9.8CVE-2024-40691Ibm cognos controller unrestricted file upload vulnerabilityIBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web in…EPSS 0.37%9.8CVE-2024-25019Ibm cognos controller unrestricted file upload vulnerabilityIBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry att…EPSS 0.28%9.8CVE-2023-38724Ibm cognos controller sql injection vulnerabilityIBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which…EPSS 0.46%9.8CVE-2020-4877Ibm cognos controller incorrect authorization vulnerabilityIBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Fo…EPSS 0.90%9.8CVE-2020-4879Ibm cognos controller improper authentication vulnerabilityIBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of auth…EPSS 1.5%8.8CVE-2026-5065Ibm controller hard-coded credentials vulnerabilityIBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own…EPSS 0.33%8.8CVE-2024-28777Ibm cognos controller deserialization of untrusted data vulnerabilityIBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allows us…EPSS 0.61%

Source: NIST National Vulnerability Database (record CVE-2025-36326), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.