Skip to content
CVE Alert: CVE-2026-18875 – IBM – Financial Transaction Manager (FTM) for RedHat OpenShift

CVE Alert: CVE-2026-18875 – IBM – Financial Transaction Manager (FTM) for RedHat OpenShift

Redpacketsecurity •admin • September 23, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent’s vector database to steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.

**Risk verdict:** This is a high-priority exposure because an unauthenticated remote attacker may influence AI-driven financial workflows; the available exploitation assessment says none, but KEV and EPSS data are not provided.

**Why this matters:** Poisoned runbooks could steer an agent into unauthorised payment actions or disclosure of sensitive transaction data. Even partial impact could undermine payment integrity, confidentiality and operational trust, with consequential investigation and recovery costs.

**Most likely attack path:** An attacker can reach the agent’s runbook interface over the network without credentials or user interaction, then add content that affects retrieval and subsequent tool use. The stated scope is unchanged, so impact is within the vulnerable component’s security authority; the extent of access to payment tools or other systems depends on deployment permissions and integrations.

**Who is most exposed:** OpenShift deployments of financial transaction platforms are most at risk where the agent API is reachable beyond a tightly controlled internal network, or where MCP tools have broad payment or data-access permissions.

Alert on unauthenticated runbook upsert requests and unexpected write volume.

Compare vector-store changes with approved runbook sources and change records.

Review agent/MCP logs for unusual payment actions, data queries or outbound transfers.

Mitigation and prioritisation

Upgrade to the vendor’s fixed release; validate the agent and payment workflows after deployment.

Until patched, restrict API ingress to trusted services and block unauthenticated writes.

Apply least privilege to agent tools; require approval for payment execution and sensitive exports.

Preserve vector-store and agent audit logs; use staged rollout and rollback planning for change control.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

Companies (1)

Platforms (1)