CVE-2026-18875: IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook
Summary
IBM Financial Transaction Manager for RedHat OpenShift has a security flaw where unauthenticated attackers can inject malicious content into the AI agent's runbook database without needing a password or login credentials, allowing them to manipulate the AI into making unauthorized payments or stealing payment information through RAG poisoning (corrupting the external documents that an AI uses to answer questions).
Vulnerability Details
7.3(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
network
low
none
none
September 23, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18875
First tracked: September 23, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 92%