Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-17635: IBM Financial Transaction Manager on OpenShift allows remote actions

CVE-2026-17635 · published 4 days ago
Summary

The IBM Financial Transaction Manager running on Red Hat OpenShift can be misconfigured so that a remote user could send special web requests and perform actions they shouldn’t be allowed to. This could let an attacker change or view transaction data without permission. Review and tighten the HTTP method security settings, or apply the latest configuration guidance from IBM.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ibm financial transaction manager (ftm) for redhat openshift <= 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064
Original advisory text
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints.
References
Severity
9.1 Critical
CVSS 3.1: 9.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published22 Sep 2026
Updated27 Sep 2026
First seen22 Sep 2026
Sources
CVE-2026-17635 · MITRE
Track software like this
Free during beta