Skip to finding
important · Zero-click

An unauthenticated client can persist instructions that steer IBM's payments agent toward unauthorized actions.

Affects

IBM Financial Transaction Manager for Red Hat OpenShift, a containerized financial-transaction processing platform with an AI-agent component.

The runbook-upsert path accepts attacker-authored content without authentication and stores it in the agent's trusted retrieval corpus. A later matching task can retrieve the poisoned runbook and steer MCP calls toward unauthorized payment actions or payment-data exfiltration.

Detail and 2 sources

We do not know whether the agent server is enabled by default or whether sensitive tool calls encounter a later approval gate. IBM has published a fix, but pre-fix images remain accepted.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 24, 2026