PT-2026-97356 · Ibm+1 · Ibm Financial Transaction Manager+1
CVE-2026-18875
·
Published
2026-09-23
·
Updated
2026-09-26
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
IBM Financial Transaction Manager (FTM) for RedHat OpenShift (affected versions not specified)
Description
The FTM AI agent server is susceptible to RAG poisoning, a technique where malicious data is injected into a Retrieval-Augmented Generation system to manipulate its output. This occurs due to an unauthenticated runbook upsert in the
api.vectordb.runbooks.js:51 file. An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool calls, which could lead to unauthorized payment actions or the exfiltration of payment data.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Financial Transaction Manager
Openshift