Unauthenticated RAG Poisoning in IBM Financial Transaction Manager Exposes MCP Tool Calls to Hijacking
IBM released a security bulletin on September 23, 2026, addressing 47 vulnerabilities in its Financial Transaction Manager (FTM) for RedHat OpenShift, including CVE-2026-18875 with a CVSS score of 7.3. This flaw allows unauthenticated attackers to poison the AI agent's vector database, potentially leading to unauthorized financial actions. The vulnerability affects FTM versions 4.0.6.0 through 4.0.10.0, and IBM recommends upgrading to version 4.0.11.0 to mitigate risks.








