Junglewise Threat Intelligence

CVE-2026-18132: IBM Financial Transaction Manager missing authorization in payment mutations

CVE-2026-18132 · Severity: medium · CVSS 6.5 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager is a financial platform that processes and manages payment transactions for enterprises. A missing authorization flaw allows authenticated attackers to perform unauthorized changes to payment transactions, potentially resulting in fraudulent payment mutations or financial loss. The vulnerability requires attacker authentication but bypasses controls on sensitive payment operations.

Technical details

The vulnerability is caused by missing authorization checks in payment mutation endpoints. An authenticated remote attacker can invoke payment modification functions without proper permission validation, allowing them to alter transaction details. The attack vector is network-based and requires prior authentication but no user interaction.

Affected products

  • IBM Financial Transaction Manager

Timeline

  • 2026-09-22: disclosed

References

Related threats