IBM disclosed a critical improper privilege management flaw in Financial Transaction Manager (FTM) for RedHat OpenShift that lets a remote, authenticated attacker escalate privileges, carrying a CVSS 3.1 base score of 9.1.
What Is It
CVE-2026-17645 is an improper privilege management vulnerability (CWE-269) in IBM Financial Transaction Manager (FTM) for RedHat OpenShift. Per IBM's advisory, the product "could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management."
The CVSS 3.1 vector is AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, no user interaction, but requiring high privileges to start. The scope is Changed, and confidentiality, integrity, and availability impacts are all High. The scope change is what pushes this into CRITICAL territory at 9.1 despite the high privilege prerequisite: a successful attacker breaks out of the component's original security authority.
Why It Matters
FTM handles financial transaction processing, so the blast radius of a privilege escalation in that stack is inherently sensitive. The Changed scope combined with High impact across all three CIA dimensions means a compromised or malicious privileged account can affect resources beyond the vulnerable component itself. Network attack vector and no required user interaction mean exploitation does not depend on tricking an operator.
The CVE record is currently in "Received" status (published 2026-09-22), and there is no entry for this CVE in the CISA Known Exploited Vulnerabilities Catalog, no confirmed active exploitation at this time.
What's Vulnerable
- Vendor: IBM
- Product: Financial Transaction Manager (FTM) for RedHat OpenShift
- Affected CPE:
cpe:2.3:a:ibm:financial_transaction_manager_ftmfor_redhat_openshift:4.0.6.0 - Versions listed as affected: 4.0.6.0 through the range IBM records as 4.0.6.0 Refresh (Operator 4.4.6+20260807.081800), 4.0.7.0, 4.0.8.0, 4.0.9.0, and 4.0.10.0 Interim Fix 064
The version range as published by IBM's PSIRT is malformed in the NVD record; operators should confirm exact affected builds against the IBM advisory directly.
Patch Status
IBM has published a support advisory for this issue. No specific fixed version or required-action deadline is stated in the supplied data; consult IBM support node 7288641 for remediation guidance and fix levels applicable to your deployment.