Junglewise Threat Intelligence

CVE-2026-18066: IBM Financial Transaction Manager server-side request forgery

CVE-2026-18066 · Severity: high · CVSS 7.9 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager (FTM) is a payment processing and financial transaction platform for OpenShift. A local attacker can exploit a server-side request forgery vulnerability to obtain sensitive information and trigger unauthorized financial actions, potentially compromising payment processing integrity and confidentiality.

Technical details

A server-side request forgery (SSRF) vulnerability in IBM FTM allows a local attacker to make the server issue requests on their behalf, enabling information disclosure and unauthorized action execution. The vulnerability requires local access and does not mandate prior authentication. A patch is expected to be available from IBM.

Affected products

  • IBM Financial Transaction Manager <UNKNOWN>

Timeline

  • 2026-09-22: disclosed

References

Related threats