ibm financial-transaction-manager-ftmfor-redhat-openshift CVE-2026-18872 is a vulnerability in IBM Financial Transaction Manager Ftmfor Redhat Openshift
Published on September 23, 2026

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator browsers, enabling session hijacking and unauthorized operator-level payment actions.

Vendor Advisory NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
NONE

Weakness Type

What is a XSS Vulnerability?

The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE-2026-18872 has been classified to as a XSS vulnerability or weakness.


Products Associated with CVE-2026-18872

Want to know whenever a new CVE is published for IBM Financial Transaction Manager Ftmfor Redhat Openshift? stack.watch will email you.

 

Affected Versions

IBM Financial Transaction Manager (FTM) for RedHat OpenShift: