Redbot Labs / Threat Intelligence
IBM Payment Agent Vulnerability Enables RAG Poisoning and Unauthorized Tool Actions
- Incident ID
- RBT-TI-0099
- Organization
- IBM
- Reported Location
- Armonk, New York, United States
- Severity
- High
- Category
- RAG Poisoning / AI Agent Tool Abuse / Payment Security
- Record Date
- 2026-09-21
Incident Summary
Poisoned agent context. IBM disclosed CVE-2026-18875, allowing unauthenticated attackers to insert malicious runbook content into the Financial Transaction Manager AI agent’s vector database.
Payment-workflow risk. The injected material could influence subsequent MCP tool calls.
What Happened
Unprotected content modification. The vulnerable runbook update mechanism accepted attacker-controlled material without authentication.
Downstream influence. Poisoned retrieval content could steer the agent toward unauthorized payment operations or payment-data exfiltration.
Remediation. IBM identifies FTM for Red Hat OpenShift version 4.0.11.0 as the fix and rates this vulnerability 7.3.
Affected Systems
FTM AI Agent Server / Runbook Ingestion / Vector Database / MCP-Connected Payment Tools
Attack Vector
Indirect Prompt Injection / Zero-Click Data Exfiltration
Business Impact
Potential financial-system misuse. Successful exploitation could affect payment actions or expose payment information.
Evidence limits. IBM’s bulletin does not identify compromised customers, successful fraudulent transactions, or quantified losses.
The technical details and remediation above are documented in IBM’s security bulletin.
Redbot Analysis
Retrieved content can become an operational influence. Redbot Labs assesses that an agent’s knowledge sources require protection comparable to other inputs that can affect business transactions. Malicious guidance becomes especially consequential when the agent can invoke tools.
Separate information from authority. Retrieved runbooks should not independently authorize payments, change transaction scope, or permit external data transfers. Connected services should enforce permissions and transaction rules regardless of the agent’s interpretation.
Protect the ingestion path. Testing should cover who can create, replace, and delete retrieval content, along with how changes are approved and attributed. Read access and write access require separate scrutiny.
Validate the complete workflow. Security testing should follow controlled poisoned content from ingestion through retrieval and tool invocation, verifying whether downstream controls prevent unauthorized outcomes.
Sources
IBM - Corporate contact information

