Junglewise Threat Intelligence

CVE-2026-17643: IBM Financial Transaction Manager insufficient credential protection

CVE-2026-17643 · Severity: high · CVSS 8.8 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager is a transaction processing platform used by financial institutions to manage critical payment and settlement operations. A local attacker with limited system access can expose stored credentials and perform unauthorized actions in the system, potentially compromising transaction integrity and customer data. This vulnerability requires local system access but can lead to lateral movement and privilege escalation within the financial infrastructure.

Technical details

CVE-2026-18124 exploits insufficiently protected credential storage (CWE-522) in FTM. A local attacker with low privileges can access the credentials due to weak protection mechanisms, bypassing authentication controls. The vulnerability requires local access to the system and results in credential disclosure enabling further unauthorized actions across the FTM infrastructure.

Affected products

  • IBM Financial Transaction Manager

Timeline

  • 2026-09-22: disclosed

References

Related threats