critical · CVSS v3 9.1
CVE-2026-17645
IBM Financial Transaction Manager (FTM) for RedHat OpenShift has a critical privilege escalation flaw that allows a remote authenticated att
Overview
IBM Financial Transaction Manager (FTM) for RedHat OpenShift has a critical privilege escalation flaw that allows a remote authenticated attacker to gain elevated privileges. The vulnerability arises from improper privilege management in the application. It can lead to unauthorized access to sensitive financial data and system control.
Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management.
Impact
Confidentiality: attackers could read or modify transaction data. Integrity: they could alter transaction records or create fraudulent entries. Availability: potential for denial of service if misused. The impact affects financial institutions and any organization running IBM FTM on RedHat OpenShift.
Remediation
Apply the latest IBM FTM security patch released on 2026-09-15. Verify that role-based access controls are correctly configured and that only authorized users have administrative privileges. Monitor audit logs for anomalous privilege escalation attempts. If patch not available, restrict network access to the FTM API and enforce least privilege.
Risk context
Severity is critical with a CVSS v3 score of 9.1. No EPSS data available. The vulnerability is exploitable by authenticated users, so organizations should prioritize patching immediately.
Affected products
- IBM FTM
- IBM Financial Transaction Manager
- IBM FTM on RedHat OpenShift
Scores
- Severity
- critical
- CVSS v2
- 8.3
- CVSS v3
- 9.1
- CVSS v4
- —
- EPSS
- —