CVE-2026-18875: IBM Financial Transaction Manager (FTM) for RedHat OpenShift vulnerability
IBM Financial Transaction Manager (FTM) 4.x is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be prioritized for investigation?
Prioritize IBM Financial Transaction Manager 4.x deployments for Red Hat OpenShift that run the FTM AI agent server, particularly where the runbook vector database can be reached by untrusted network clients.
Does an attacker need credentials to exploit this issue?
No. The issue is described as an unauthenticated runbook upsert, so an attacker does not need authentication to insert malicious runbook content.
What operational impact could poisoned runbooks have?
Poisoned content can steer AI-driven MCP tool calls. The stated potential outcomes include unauthorized payment actions and exfiltration of payment data.