Executive brief
IBM Financial Transaction Manager (FTM) is enterprise software that processes financial transactions and payment operations. A remote authenticated attacker can execute arbitrary code on the system by exploiting improper validation of input parameters, potentially leading to unauthorized access to financial data, fraudulent transactions, or system compromise.
Technical details
CVE-2026-17636 exploits improper validation of a specified quantity parameter, allowing a network-based authenticated attacker to achieve remote code execution. The vulnerability requires valid authentication credentials but no additional user interaction. Successful exploitation grants an attacker the ability to execute arbitrary code with the privileges of the FTM application.
Affected products
- IBM Financial Transaction Manager unspecified
Timeline
- 2026-09-22: disclosed