Stored Cross-Site Scripting in IBM Financial Transaction Manager for RedHat OpenShift
CVE-2026-18872
9.3CRITICAL
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 23 September 2026
What is CVE-2026-18872?
IBM Financial Transaction Manager for RedHat OpenShift is susceptible to a stored cross-site scripting vulnerability within the NetworkAcknowledgement React component. This flaw allows an attacker to inject malicious scripts into the stored network acknowledgement data. When authenticated operators view this data, the script executes in their browsers, which can lead to session hijacking and the potential for unauthorized actions related to payment processing.
Affected Version(s)
Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 <= 4.0.10.0