CVE-2026-17618
📛 CVE Title
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- ibm
- CVSS severity
- HIGH
- CVSS score
- 7.3 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L- Effective score
- 7.3 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-862 - Reserved
- 2026-07-27
- Published
- 2026-09-22 21:27 UTC
- Last updated
- 2026-09-22 21:27 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/17xxx/CVE-2026-17618.json
- Linked Threat
- CVE-2026-17618 — IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-22 22:17:07 UTC
- NVD last modified
- 2026-09-22 22:17:07 UTC
- NVD CVSS v3.1
- 7.3 / 10 HIGH source: psirt@us.ibm.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 3.4 / 10
NVD / KEV / EPSS data refreshed 2026-09-23 01:43 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-84969 - Assigner
- ibm
- Published
- Sep 22, 2026, 9:27:46 PM
- Updated
- Sep 22, 2026, 9:27:46 PM
- EUVD base score (CVSS 3.1)
-
7.3 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L - EUVD-reported EPSS
- 0.0000
- Vendors
- IBM
- Products
-
Financial Transaction Manager (FTM) for RedHat OpenShift (4.0.6.0 ≤4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064)
- Aliases
-
GHSA-r2w9-pqjq-xghh
ENISA description: IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.
EUVD references (1)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| IBM | Financial Transaction Manager (FTM) for RedHat OpenShift |
4.0.6.0 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- https://www.ibm.com/support/pages/node/7288641 vendor-advisorypatch
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (1)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://www.ibm.com/support/pages/node/7288641 psirt@us.ibm.com
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:app.opencve.io
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.
2026-09-23 15:20 UTC -
web:cvetodo.com
CVE-2026-17618 is a CVSS 7.3 high-severity vulnerability in IBM products. Includes technical details, affected versions, and mitigation steps.
2026-09-23 15:20 UTC -
web:feedly.com
A vulnerability categorized as very critical has been discovered in IBM Financial Transaction Manager . This vulnerability affects unknown code. Such manipulation leads to improper authorization. This vulnerability is uniquely identified as CVE-2026-17618 . The attack can be launched remotely. No exploit exists.
2026-09-23 15:20 UTC -
web:senserva.com
Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.
2026-09-23 15:20 UTC -
web:support.servicenow.com
Due to additional analysis provided by the security researcher who discovered CVE - 2026 -6876, we have upgraded the severity rating of CVE - 2026 -6876 from High to Critical. This change affects only the severity
2026-09-23 15:20 UTC -
web:vulmon.com
Vulnerability Summary IBM Financial Transaction Manager (FTM) for RedHat OpenShift has an improper authorization flaw. This enables a remote, unauthenticated attacker to view and modify sensitive information, and also to cause a denial of service.
2026-09-23 15:20 UTC -
web:vulners.com
CVE-2026-17618 🗓️ 22 Sep 2026 14:27:46 Reported by ibm Type cve 🔗 web.nvd.nist.gov 👁 4 Views
2026-09-23 15:20 UTC -
web:www.oracle.com
This Critical Patch Update contains 1448 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at July 2026 Critical Patch Update: Executive Summary and Analysis.
2026-09-23 15:20 UTC -
web:www.tenable.com
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.
2026-09-23 15:20 UTC -
web:www.wiz.io
Understand the critical aspects of CVE - 2026 -86218 with a detailed vulnerability assessment, exploitation potential, affected technologies, and remediation guidance.
2026-09-23 15:20 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-17618.json.
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:ibm:financial_transaction_manager_ftmfor_redhat_openshift:4.0.6.0:*:*:*:*:*:*:*"
],
"product": "Financial Transaction Manager (FTM)\u00a0for RedHat OpenShift",
"vendor": "IBM",
"versions": [
{
"lessThanOrEqual": "4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064",
"status": "affected",
"version": "4.0.6.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.</p>"
}
],
"value": "IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T21:27:46.316Z",
"orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"shortName": "ibm"
},
"references": [
{
"tags": [
"vendor-advisory",
"patch"
],
"url": "https://www.ibm.com/support/pages/node/7288641"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>IBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following</p><p></p><div><table><tbody><tr><td>Affected Product(s)</td><td>Resolved by VRMF</td><td>Remediation / First Fix</td></tr><tr><td>Financial Transaction Manager (FTM)\u00a0for RedHat OpenShift</td><td>4.0.11.0</td><td><a href=\"https://www.ibm.com/support/pages/node/7285661\" rel=\"nofollow\">FTM 4.0.11.0</a></td></tr></tbody></table></div>"
}
],
"value": "IBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following\n\n\n\n\n\nAffected Product(s)Resolved by VRMFRemediation / First FixFinancial Transaction Manager (FTM)\u00a0for RedHat OpenShift4.0.11.0 FTM 4.0.11.0 https://www.ibm.com/support/pages/node/7285661"
}
],
"title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities"
}
},
"cveMetadata": {
"assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"assignerShortName": "ibm",
"cveId": "CVE-2026-17618",
"datePublished": "2026-09-22T21:27:46.316Z",
"dateReserved": "2026-07-27T20:26:49.744Z",
"dateUpdated": "2026-09-22T21:27:46.316Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}