Improper Path Canonicalization in IBM Financial Transaction Manager for RedHat OpenShift
CVE-2026-18114
6.5MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 22 September 2026
What is CVE-2026-18114?
A vulnerability exists in the IBM Financial Transaction Manager for RedHat OpenShift that allows a remote attacker to exploit improper path canonicalization. This flaw enables unauthorized reading of arbitrary files, potentially exposing sensitive information and compromising the system's security integrity. This security issue emphasizes the importance of strict validation in file handling to prevent unauthorized data access.
Affected Version(s)
Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 <= 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064