An unauthenticated client can persist instructions that steer IBM's payments agent toward unauthorized actions.
IBM Financial Transaction Manager for Red Hat OpenShift, a containerized financial-transaction processing platform with an AI-agent component.
The runbook-upsert path accepts attacker-authored content without authentication and stores it in the agent's trusted retrieval corpus. A later matching task can retrieve the poisoned runbook and steer MCP calls toward unauthorized payment actions or payment-data exfiltration.
Detail and 2 sources
We do not know whether the agent server is enabled by default or whether sensitive tool calls encounter a later approval gate. IBM has published a fix, but pre-fix images remain accepted.