Junglewise Threat Intelligence

CVE-2026-18161: IBM Financial Transaction Manager audit log falsification via HTTP header validation

CVE-2026-18161 · Severity: medium · CVSS 4.3 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager (FTM), a system that processes and manages financial transactions for organizations, contains a vulnerability that allows authenticated attackers to falsify transaction audit logs through improper validation of HTTP headers. This means attackers could tamper with the audit trail to hide unauthorized transactions or cover their tracks, undermining compliance and forensic investigation capabilities.

Technical details

An authenticated attacker can exploit improper validation of a client-supplied HTTP header to falsify transaction audit logs in IBM FTM. The vulnerability requires prior authentication but allows an attacker with valid credentials to manipulate audit records via a network-based attack. A fix is available from IBM.

Affected products

  • IBM Financial Transaction Manager 4.x and earlier

Timeline

  • 2026-09-22: disclosed

References

Related threats