Junglewise Threat Intelligence

CVE-2026-17646: IBM Financial Transaction Manager XML external entity reference denial of information

CVE-2026-17646 · Severity: high · CVSS 8.5 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager (FTM) is a payment processing system used to manage financial transactions in enterprise environments. An authenticated attacker can exploit improper handling of XML input to access sensitive information like credentials, account details, or system configuration data. This could lead to further compromise of the financial transaction system and exposure of customer data.

Technical details

The vulnerability stems from improper restriction of XML external entity (XXE) references in FTM's XML parsing logic, allowing an authenticated network-based attacker to read arbitrary files or access internal system resources. The attacker must have valid authentication credentials but can then retrieve sensitive information without further authorization. The issue affects FTM's core XML processing without requiring user interaction.

Affected products

  • IBM Financial Transaction Manager

Timeline

  • 2026-09-22: disclosed

References

Related threats