Junglewise Threat Intelligence

CVE-2026-17618: IBM Financial Transaction Manager remote authentication bypass and information disclosure

CVE-2026-17618 · Severity: high · CVSS 7.3 · Published 2026-09-22

Vendors: IBM.

Executive brief

IBM Financial Transaction Manager (FTM) is enterprise software for processing financial transactions on OpenShift. Multiple vulnerabilities allow remote unauthenticated attackers to view and modify sensitive financial data, execute unauthorized payments, and cause service outages without authentication. These flaws expose organizations to data theft, fraud, and operational disruption.

Technical details

The primary vulnerability (CVE-2026-18185) is a missing authentication check on critical REST endpoints, allowing unauthenticated network access to view and modify system configurations and sensitive information. Additional critical flaws include improper authorization controls (CVE-2026-18177, CVE-2026-18179), unsafe reflection causing DoS (CVE-2026-18123), XML external entity injection (CVE-2026-18172), and hardcoded cryptographic keys in authenticated flows. Attack vectors span network and adjacent network with minimal prerequisites; patches are available from IBM.

Affected products

  • IBM Financial Transaction Manager 4.x and earlier

Timeline

  • 2026-09-22: disclosed

References

Related threats