← Back to search

CVE-2026-17645

9.1 CRITICAL

Published 2026-09-22 · Updated 2026-09-23

AI risk analysis

Summary
The flaw in IBM Financial Transaction Manager (FTM) for RedHat OpenShift allows a remote attacker with authentication to gain elevated privileges, due to improper privilege management.
Exploitability
Exploitation requires a valid authentication, making it moderately hard to exploit. Precondition is the presence of a remote attacker with valid credentials.
Blast radius
If exploited, the attacker could gain elevated privileges, potentially leading to full system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest version of IBM FTM for RedHat OpenShift.
auth-bypasspriv-escalationremoteredhat

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-269

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.