rootpwn

critical · CVSS v3 9.1

CVE-2026-17645

IBM Financial Transaction Manager (FTM) for RedHat OpenShift has a critical privilege escalation flaw that allows a remote authenticated att

Overview

IBM Financial Transaction Manager (FTM) for RedHat OpenShift has a critical privilege escalation flaw that allows a remote authenticated attacker to gain elevated privileges. The vulnerability arises from improper privilege management in the application. It can lead to unauthorized access to sensitive financial data and system control.

Description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management.

Impact

Confidentiality: attackers could read or modify transaction data. Integrity: they could alter transaction records or create fraudulent entries. Availability: potential for denial of service if misused. The impact affects financial institutions and any organization running IBM FTM on RedHat OpenShift.

Remediation

Apply the latest IBM FTM security patch released on 2026-09-15. Verify that role-based access controls are correctly configured and that only authorized users have administrative privileges. Monitor audit logs for anomalous privilege escalation attempts. If patch not available, restrict network access to the FTM API and enforce least privilege.

Risk context

Severity is critical with a CVSS v3 score of 9.1. No EPSS data available. The vulnerability is exploitable by authenticated users, so organizations should prioritize patching immediately.

Affected products

  • IBM FTM
  • IBM Financial Transaction Manager
  • IBM FTM on RedHat OpenShift

Scores

Severity
critical
CVSS v2
8.3
CVSS v3
9.1
CVSS v4
EPSS

privilege-escalation IBM FTM RedHat OpenShift critical authentication RBAC

← All CVEs