critical · CVSS v3 8.8
CVE-2026-17636
IBM Financial Transaction Manager (FTM) for RedHat OpenShift has a critical flaw that allows a remote authenticated attacker to execute arbi
Overview
IBM Financial Transaction Manager (FTM) for RedHat OpenShift has a critical flaw that allows a remote authenticated attacker to execute arbitrary code by exploiting improper quantity validation. The vulnerability can be leveraged to compromise the entire transaction processing environment. It is relevant to organizations running FTM on OpenShift clusters.
Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity.
Impact
The flaw violates confidentiality, integrity, and availability of the transaction system. Attackers can gain full control over the FTM instance, potentially exposing sensitive financial data and disrupting transaction processing. Defenders must consider the risk to all users and services relying on FTM.
Remediation
Apply the latest IBM FTM security patch or upgrade to a version that fixes the quantity validation issue. Restrict authentication to trusted users and enforce least privilege. Monitor OpenShift logs for anomalous API calls and consider network segmentation to isolate FTM components.
Risk context
Severity is critical with a CVSS v3 score of 8.8. The lack of an EPSS score suggests no publicly available exploit data yet, but the critical rating warrants immediate attention and patching.
Affected products
- IBM FTM
- RedHat OpenShift
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 8.8
- CVSS v4
- —
- EPSS
- —