high · CVSS v3 8.2
CVE-2026-18074
IBM Financial Transaction Manager (FTM) for RedHat OpenShift has a high severity flaw that allows remote attackers to bypass authentication
Overview
IBM Financial Transaction Manager (FTM) for RedHat OpenShift has a high severity flaw that allows remote attackers to bypass authentication and perform unauthorized actions. The vulnerability stems from improper authentication and missing authorization controls. It can be exploited without user interaction, potentially compromising financial transaction processing.
Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization.
Impact
Confidentiality: attackers can read or modify transaction data. Integrity: unauthorized transaction creation or alteration. Availability: potential for denial of service by flooding the system. Defenders: system administrators, security teams managing IBM FTM deployments.
Remediation
Apply the latest IBM FTM security patch or update to the latest version. Verify that authentication mechanisms are enabled and properly configured. Enforce role-based access control and least privilege. Restrict network access to FTM services to trusted IP ranges and monitor for anomalous activity.
Risk context
Severity is high with a CVSS v3 score of 8.2. No EPSS data available. The vulnerability can be exploited remotely, so timely patching is critical.
Affected products
- IBM Financial Transaction Manager
- IBM FTM for RedHat OpenShift
Scores
- Severity
- high
- CVSS v2
- 8.5
- CVSS v3
- 8.2
- CVSS v4
- —
- EPSS
- —