CVE-2026-93030: XEE
Published Sep 25, 2026
·Updated
FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.
Affected Software
1 affected component
FTM=4.x
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Financial Transaction Manager (FTM) for Red Hat OpenShiftto a version that resolves this vulnerability.Fixed in 4.0.11.0
Event History
Sep 25, 2026
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker must be authenticated and have low privileges. No user interaction is required.
2
What is the potential impact?
Successful exploitation could disclose sensitive information. The available data does not indicate integrity or availability impact.
3
Is exploitation possible over the network?
Yes. The attack vector is network-based and has low attack complexity.