CVE-2026-18875
Awaiting Analysis Awaiting Analysis - Queue

Unauthenticated RAG Poisoning in IBM FTM for RedHat OpenShift

Vulnerability report for CVE-2026-18875, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: IBM Corporation

Description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-24
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm financial_transaction_manager *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning. An unauthenticated attacker can insert malicious runbook content into the AI agent's vector database. This could manipulate AI-driven tool calls, potentially leading to unauthorized actions or data theft.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized runbook insertions in the FTM AI agent server's vector database. Monitor logs for unexpected API calls to api.vectordb.runbooks.js and inspect database entries for suspicious or unauthorized content. No specific commands are provided in the context.

Impact Analysis

An attacker could use this flaw to trigger unauthorized payment actions or steal sensitive payment data. The vulnerability allows manipulation of AI-driven decisions without authentication, posing risks to financial transactions and data security.

Compliance Impact

This vulnerability could lead to unauthorized data access or transactions, violating GDPR (data protection) and HIPAA (healthcare data privacy). Non-compliance risks include legal penalties, reputational damage, and loss of trust in financial systems handling sensitive data.

Mitigation Strategies

Immediately restrict network access to the FTM AI agent server to prevent unauthenticated runbook upserts. Review and validate all existing runbooks in the vector database for unauthorized modifications. Apply vendor patches or updates if available from IBM for this specific vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18875. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart