OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-18505

MEDIUM · CVSS 5.4 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

IBM Financial Transaction Manager for RedHat OpenShift is vulnerable to an open redirect due to improper handling of the `Host` header in the PMP `HostHeaderFilter`. This flaw allows unauthenticated attackers to redirect authenticated users to malicious sites, potentially facilitating credential phishing attacks. Organizations utilizing this software should prioritize remediation to protect their users from phishing threats.

CVE
CVE-2026-18505
Severity
MEDIUM
CVSS
5.4
EPSS
0.15%
Java

Original NVD Description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect authenticated operators to attacker-controlled sites, enabling credential phishing.

Related CVEs

Other vulnerabilities affecting the same vendor(s)