IBM Financial Transaction Manager Hit with Critical RAG Poisoning Vulnerability
A critical vulnerability has been discovered in IBM's Financial Transaction Manager (FTM) for RedHat OpenShift platform. The issue, known as CVE-2026-18875, allows an unauthenticated attacker to execute a network-based runbook upsert and inject malicious content into the vector database used by the AI agent.
The vulnerability is particularly concerning because it can be exploited to hijack MCP tool calls, forcing the system to perform unauthorized payment actions or exfiltrate sensitive financial data. This highlights the increasing complexity of securing AI-integrated financial infrastructure, specifically regarding the integrity of Retrieval-Augmented Generation (RAG) pipelines.
The FTM implementation demonstrates how minimal document injection into a vector store can be sufficient to hijack agent operations, effectively turning the agent's own retrieval mechanism against the integrity of the financial transaction environment. The presence of other severe flaws in the same bulletin underscores the need for a comprehensive review of both AI-specific and traditional code execution paths.