CVE-2026-18872 is a vulnerability in IBM Financial Transaction Manager Ftmfor Redhat Openshift
Published on September 23, 2026
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator browsers, enabling session hijacking and unauthorized operator-level payment actions.
Vulnerability Analysis
Weakness Type
What is a XSS Vulnerability?
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2026-18872 has been classified to as a XSS vulnerability or weakness.
Products Associated with CVE-2026-18872
Want to know whenever a new CVE is published for IBM Financial Transaction Manager Ftmfor Redhat Openshift? stack.watch will email you.
Affected Versions
IBM Financial Transaction Manager (FTM) for RedHat OpenShift:- Version 4.0.6.0, <= 4.0.10.0 is affected.