Junglewise Threat Intelligence

CVE-2026-18137: IBM Financial Transaction Manager ESQL command injection

CVE-2026-18137 · Severity: high · CVSS 8.1 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager is a financial transaction processing system used by enterprises to manage payments and financial operations. A remote attacker can execute arbitrary ESQL database commands due to improper input validation, potentially leading to unauthorized data access, modification, or deletion of financial records.

Technical details

The vulnerability is caused by improper neutralization of special elements in ESQL commands, allowing command injection attacks. An attacker can craft malicious input that breaks out of intended command syntax to execute arbitrary database operations. This is a network-accessible vulnerability requiring no authentication, with a CVSS score of 8.1.

Affected products

  • IBM Financial Transaction Manager 4.x and earlier

Timeline

  • 2026-09-22: disclosed

References

Related threats