rootpwn

critical · CVSS v3 8.8

CVE-2026-17636

IBM Financial Transaction Manager (FTM) for RedHat OpenShift has a critical flaw that allows a remote authenticated attacker to execute arbi

Overview

IBM Financial Transaction Manager (FTM) for RedHat OpenShift has a critical flaw that allows a remote authenticated attacker to execute arbitrary code by exploiting improper quantity validation. The vulnerability can be leveraged to compromise the entire transaction processing environment. It is relevant to organizations running FTM on OpenShift clusters.

Description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity.

Impact

The flaw violates confidentiality, integrity, and availability of the transaction system. Attackers can gain full control over the FTM instance, potentially exposing sensitive financial data and disrupting transaction processing. Defenders must consider the risk to all users and services relying on FTM.

Remediation

Apply the latest IBM FTM security patch or upgrade to a version that fixes the quantity validation issue. Restrict authentication to trusted users and enforce least privilege. Monitor OpenShift logs for anomalous API calls and consider network segmentation to isolate FTM components.

Risk context

Severity is critical with a CVSS v3 score of 8.8. The lack of an EPSS score suggests no publicly available exploit data yet, but the critical rating warrants immediate attention and patching.

Affected products

  • IBM FTM
  • RedHat OpenShift

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.8
CVSS v4
EPSS

remote code execution authentication bypass IBM FTM OpenShift critical CVE-2026-17636

← All CVEs