Junglewise Threat Intelligence

CVE-2026-17635: IBM Financial Transaction Manager improper HTTP security constraints

CVE-2026-17635 · Severity: critical · CVSS 9.1 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager (FTM) is a financial transaction processing platform deployed on RedHat OpenShift. Improper configuration of HTTP method-based security constraints allows remote attackers to bypass access controls and perform unauthorized financial or administrative actions without proper authentication. This could lead to fraudulent transactions, data theft, or system compromise.

Technical details

The vulnerability stems from inadequate enforcement of HTTP method-based security constraints, allowing unauthenticated or low-privileged remote attackers to invoke protected operations via HTTP requests. The flaw permits direct access to sensitive endpoints that should require authentication or higher privilege levels. A patch is available from IBM.

Affected products

  • IBM Financial Transaction Manager

Timeline

  • 2026-09-22: disclosed

References

Related threats