Junglewise Threat Intelligence

CVE-2026-17644: IBM Financial Transaction Manager hard-coded credentials local escalation

CVE-2026-17644 · Severity: high · CVSS 8.8 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager (FTM) for RedHat OpenShift, which processes critical financial transactions, contains hard-coded credentials that allow local attackers to gain unauthorized system access and modify transaction data. An attacker with local access to the system can exploit this vulnerability to impersonate legitimate users and alter financial transactions, bypassing security controls and potentially causing financial loss or data tampering.

Technical details

CVE-2026-17644 exploits insufficiently protected credentials (hard-coded credentials) in FTM, allowing local privilege escalation and unauthorized access to sensitive transaction information. The vulnerability requires local access to the system but no authentication, enabling credential extraction and subsequent system compromise. This is a classic weak credential management issue that permits both information disclosure and integrity violations of financial transaction data.

Affected products

  • IBM Financial Transaction Manager 4.x

Timeline

  • 2026-09-22: disclosed

References

Related threats