Executive brief
IBM Financial Transaction Manager (FTM) is a financial services platform that processes and manages transactions for enterprises. Multiple critical security flaws allow unauthenticated and authenticated remote attackers to bypass security controls, execute unauthorized payment actions, modify system configurations, and access sensitive data. These vulnerabilities could enable account takeover, fraud, data breaches, and denial of service attacks on financial systems.
Technical details
The vulnerabilities include missing authentication on critical endpoints (CVE-2026-18185, CVE-2026-19267), improper authorization checks (CVE-2026-18074, CVE-2026-18177, CVE-2026-18179), certificate validation flaws (CVE-2026-18173), hardcoded cryptographic keys (CVE-2026-18153), path traversal (CVE-2026-18133), stored XSS (CVE-2026-18131), open redirect (CVE-2026-18505), unsafe reflection (CVE-2026-18123), XML external entity injection (CVE-2026-18172), and credential protection issues (CVE-2026-18124). Attack vectors range from network-based unauthenticated access to local privilege escalation, requiring minimal or no user interaction for exploitation.
Affected products
- IBM Financial Transaction Manager 4.x and earlier
Timeline
- 2026-09-22: disclosed