Junglewise Threat Intelligence

CVE-2026-17645: IBM Financial Transaction Manager privilege escalation

CVE-2026-17645 · Severity: critical · CVSS 9.1 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager (FTM), a financial transaction processing system running on Red Hat OpenShift, allows authenticated remote attackers to gain elevated privileges through improper privilege management controls. Successful exploitation could enable unauthorized users to perform administrative actions, modify system configurations, and access or alter sensitive financial transaction data.

Technical details

A privilege management flaw in FTM allows authenticated remote attackers to escalate their privileges without additional authentication or interaction. The vulnerability stems from insufficient authorization checks that fail to properly restrict access to critical functions based on user roles. Exploitation results in complete system compromise with ability to execute privileged operations.

Affected products

  • IBM Financial Transaction Manager <UNKNOWN>

Timeline

  • 2026-09-22: disclosed

References

Related threats