Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-18872: IBM FTM on OpenShift runs malicious script in admin browser

CVE-2026-18872 · published 3 days ago
Summary

The IBM Financial Transaction Manager running on Red Hat OpenShift can be tricked into storing harmful code in its network acknowledgement screen. When an authorized operator views the tampered data, the code runs in their browser, potentially stealing their session and allowing unauthorized payment actions. Apply the latest IBM security updates and ensure input validation is enforced to prevent script injection.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ibm financial transaction manager (ftm) for redhat openshift <= 4.0.10.0
Original advisory text
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator browsers, enabling session hijacking and unauthorized operator-level payment actions.
References
Severity
9.3 Critical
CVSS 3.1: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published23 Sep 2026
Updated27 Sep 2026
First seen23 Sep 2026
Sources
CVE-2026-18872 · MITRE
Track software like this
Free during beta