Redbot Labs / Threat Intelligence

IBM Payment Agent Vulnerability Enables RAG Poisoning and Unauthorized Tool Actions

Incident ID
RBT-TI-0099
Organization
IBM
Reported Location
Armonk, New York, United States
Severity
High
Category
RAG Poisoning / AI Agent Tool Abuse / Payment Security
Record Date
2026-09-21

Incident Summary

Poisoned agent context. IBM disclosed CVE-2026-18875, allowing unauthenticated attackers to insert malicious runbook content into the Financial Transaction Manager AI agent’s vector database.
Payment-workflow risk. The injected material could influence subsequent MCP tool calls.

What Happened

Unprotected content modification. The vulnerable runbook update mechanism accepted attacker-controlled material without authentication.

Downstream influence. Poisoned retrieval content could steer the agent toward unauthorized payment operations or payment-data exfiltration.

Remediation. IBM identifies FTM for Red Hat OpenShift version 4.0.11.0 as the fix and rates this vulnerability 7.3.

Affected Systems

FTM AI Agent Server / Runbook Ingestion / Vector Database / MCP-Connected Payment Tools

Attack Vector

Indirect Prompt Injection / Zero-Click Data Exfiltration

Business Impact

Potential financial-system misuse. Successful exploitation could affect payment actions or expose payment information.

Evidence limits. IBM’s bulletin does not identify compromised customers, successful fraudulent transactions, or quantified losses.

The technical details and remediation above are documented in IBM’s security bulletin.

Redbot Analysis

Retrieved content can become an operational influence. Redbot Labs assesses that an agent’s knowledge sources require protection comparable to other inputs that can affect business transactions. Malicious guidance becomes especially consequential when the agent can invoke tools.

Separate information from authority. Retrieved runbooks should not independently authorize payments, change transaction scope, or permit external data transfers. Connected services should enforce permissions and transaction rules regardless of the agent’s interpretation.

Protect the ingestion path. Testing should cover who can create, replace, and delete retrieval content, along with how changes are approved and attributed. Read access and write access require separate scrutiny.

Validate the complete workflow. Security testing should follow controlled poisoned content from ingestion through retrieval and tool invocation, verifying whether downstream controls prevent unauthorized outcomes.

Sources

Read the primary source

IBM - Corporate contact information

Related Attack Intelligence