Executive brief
IBM Financial Transaction Manager is a transaction processing platform used by financial institutions to manage critical payment and settlement operations. A local attacker with limited system access can expose stored credentials and perform unauthorized actions in the system, potentially compromising transaction integrity and customer data. This vulnerability requires local system access but can lead to lateral movement and privilege escalation within the financial infrastructure.
Technical details
CVE-2026-18124 exploits insufficiently protected credential storage (CWE-522) in FTM. A local attacker with low privileges can access the credentials due to weak protection mechanisms, bypassing authentication controls. The vulnerability requires local access to the system and results in credential disclosure enabling further unauthorized actions across the FTM infrastructure.
Affected products
- IBM Financial Transaction Manager
Timeline
- 2026-09-22: disclosed