Junglewise Threat Intelligence

CVE-2026-18172: IBM Financial Transaction Manager XXE information disclosure

CVE-2026-18172 · Severity: high · CVSS 7.4 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager (FTM) is a payment processing platform used by financial institutions to manage transaction workflows. A flaw in its XML parsing allows a remote attacker to extract sensitive information such as system files or configuration data without authentication. An attacker can weaponize this to steal credentials, API keys, or transaction details.

Technical details

The vulnerability is a classic XML External Entity (XXE) injection in improper restriction of XML external entity references (CWE-611). An unauthenticated attacker can submit crafted XML payloads over the network with low complexity; the attack requires adjacent network access. Successful exploitation results in information disclosure of sensitive data accessible to the application.

Affected products

  • IBM Financial Transaction Manager

Timeline

  • 2026-09-22: disclosed

References

Related threats