RAG Poisoning in IBM Financial Transaction Manager for RedHat OpenShift
CVE-2026-18875

7.3HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
23 September 2026

What is CVE-2026-18875?

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is susceptible to RAG poisoning due to an unauthenticated runbook upsert in the FTM AI agent server. This vulnerability enables an unauthenticated attacker to insert harmful runbook content into the agent's vector database. Consequently, this manipulation can lead to the potential steering of AI-driven Multi-Channel Processing (MCP) tool calls, which may result in unauthorized payment actions or the exfiltration of sensitive payment data.

Affected Version(s)

Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 <= 4.0.10.0

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.