{"data":{"id":"00b5cdbe-674d-4404-84fd-6f095e2d8063","title":"CVE-2026-18875: IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook ","summary":"IBM Financial Transaction Manager for RedHat OpenShift has a security flaw where unauthenticated attackers can inject malicious content into the AI agent's runbook database without needing a password or login credentials, allowing them to manipulate the AI into making unauthorized payments or stealing payment information through RAG poisoning (corrupting the external documents that an AI uses to answer questions).","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18875","publishedAt":"2026-09-23T16:16:41.850Z","cveId":"CVE-2026-18875","cweIds":["CWE-74"],"cvssScore":"7.3","cvssSeverity":"high","severity":"high","attackType":["rag_poisoning"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["IBM Financial Transaction Manager","IBM FTM","RedHat OpenShift"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-23T16:16:41.850Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"rag","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0020","AML.T0051.001"]}}