Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-17645: IBM FTM on OpenShift may let attackers gain admin rights
CVE-2026-17645 · published 4 days ago
Summary
The IBM Financial Transaction Manager running on Red Hat OpenShift has a weakness that could let a user who is already logged in increase their access level. This could allow the user to perform actions they should not be able to do, potentially affecting transaction processing. Apply the latest IBM security updates or patches to correct the privilege handling.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | financial transaction manager (ftm) for redhat openshift | <= 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064 |
Original advisory text
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management.
References
- https://www.ibm.com/support/pages/node/7288641 vendor-advisory patch
Severity
9.1
Critical
CVSS 3.1: 9.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published22 Sep 2026
Updated27 Sep 2026
First seen22 Sep 2026
Track software like this
Free during beta