Junglewise Threat Intelligence

CVE-2026-18169: IBM Financial Transaction Manager symbolic link validation bypass

CVE-2026-18169 · Severity: critical · CVSS 9.9 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager (FTM), a financial transaction processing system for enterprise environments, contains a flaw in how it validates symbolic links. A remote attacker with authentication credentials could exploit this to read sensitive files on the system, potentially exposing transaction data, customer information, or other confidential business records.

Technical details

The vulnerability exists due to improper validation of symbolic links in FTM, allowing an authenticated remote attacker to access sensitive information through symlink traversal. An attacker must be authenticated to the system but can then traverse symbolic links to read files outside intended directories. The vulnerability affects FTM running on RedHat OpenShift environments.

Affected products

  • IBM Financial Transaction Manager

Timeline

  • 2026-09-22: disclosed

References

Related threats