{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-18875/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:redhat_openshift:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-17635"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Financial Transaction Manager for RedHat OpenShift","Financial Transaction Manager (for RedHat OpenShift)","Financial Transaction Manager (for Red Hat OpenShift)"],"_cs_severities":["critical"],"_cs_tags":["web-vulnerability","security-misconfiguration","financial-services","cve-2026-17635","cross-site-scripting","cve-2026-18872","ai-security","rag-poisoning","cve-2026-18875"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM Financial Transaction Manager (FTM) for RedHat OpenShift suffers from a critical security misconfiguration related to the enforcement of HTTP method-based security constraints. This vulnerability, identified as CVE-2026-17635, permits a remote, unauthenticated attacker to manipulate HTTP requests to evade intended access control mechanisms. By utilizing specific HTTP methods that were not properly restricted during the application's configuration, an attacker can perform unauthorized actions within the transaction management environment. Given the nature of this software in processing financial transactions, the successful exploitation of this vulnerability poses a significant risk to the integrity and confidentiality of high-value transaction data. Defenders should prioritize auditing the configuration of their FTM instances and monitoring for unusual HTTP method usage directed at the application API.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthorized access to core transaction management functions, which could result in unauthorized transaction initiation, modification, or exposure of sensitive financial data. Failure to remediate this misconfiguration within the production environment may lead to severe operational and financial disruption, as well as a compromise of regulatory compliance requirements associated with financial transaction processing systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate audit of all IBM Financial Transaction Manager for RedHat OpenShift deployments for security misconfigurations.\nImplement strict HTTP request filtering at the web application firewall or OpenShift ingress level to ensure only authorized methods are permitted for specific API endpoints.\nEnsure that security patches or configuration updates provided by IBM for CVE-2026-17635 are applied to all instances.\nMonitor web server logs for HTTP methods that deviate from the expected traffic patterns for specific application paths.\u003c/p\u003e\n","date_modified":"2026-09-23T16:43:48Z","date_published":"2026-09-22T22:39:56Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ibm-ftm-security-misconfiguration/","summary":"IBM Financial Transaction Manager for RedHat OpenShift is vulnerable to an improper configuration of HTTP method-based security constraints, allowing remote unauthenticated attackers to bypass access controls.","title":"Security Misconfiguration in IBM Financial Transaction Manager for RedHat OpenShift","url":"https://feed.craftedsignal.io/briefs/2026-09-ibm-ftm-security-misconfiguration/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-18875","version":"https://jsonfeed.org/version/1.1"}