Junglewise Threat Intelligence

CVE-2026-18124: IBM Financial Transaction Manager local credential exposure

CVE-2026-18124 · Severity: medium · CVSS 6.5 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager (FTM) is middleware that processes financial transactions and business operations. A local attacker with limited privileges can read insufficiently protected credentials from the system, potentially gaining unauthorized access to sensitive financial data or elevated system capabilities. This could lead to fraudulent transactions, data theft, or further system compromise.

Technical details

CWE-522: Insufficiently Protected Credentials. The vulnerability allows a local attacker with low privileges to access plaintext or weakly protected credentials stored on the system. Attack requires local system access but no elevated privileges. An attacker gains the ability to read credentials that provide high-confidentiality access across the system scope.

Affected products

  • IBM Financial Transaction Manager

Timeline

  • 2026-09-22: disclosed

References

Related threats