RAG Poisoning in IBM Financial Transaction Manager for RedHat OpenShift
CVE-2026-18875
7.3HIGH
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 23 September 2026
What is CVE-2026-18875?
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is susceptible to RAG poisoning due to an unauthenticated runbook upsert in the FTM AI agent server. This vulnerability enables an unauthenticated attacker to insert harmful runbook content into the agent's vector database. Consequently, this manipulation can lead to the potential steering of AI-driven Multi-Channel Processing (MCP) tool calls, which may result in unauthorized payment actions or the exfiltration of sensitive payment data.
Affected Version(s)
Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 <= 4.0.10.0