CVE-2026-18872: IBM Financial Transaction Manager (FTM) for RedHat OpenShift vulnerability
IBM Financial Transaction Manager (FTM) 4.x is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator browsers, enabling session hijacking and unauthorized operator-level payment actions.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Authenticated FTM operators who use the FTM UI and view stored network acknowledgement data are exposed, because injected script executes in their browsers.
What access does an attacker need to exploit it?
The attacker needs a way to inject malicious script into stored network acknowledgement data. The provided information does not identify the required application role or input path.
What could successful exploitation allow?
A successful attack can hijack an authenticated operator session and perform unauthorized payment actions with that operator's privileges.