{"id":"CVE-2026-18872","published":"2026-09-23T16:16:41.720","lastModified":"2026-09-23T19:17:29.493","description":"IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator browsers, enabling session hijacking and unauthorized operator-level payment actions.","cvssScore":9.3,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288641","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows a malicious actor to inject script into stored network acknowledgement data, leading to session hijacking and unauthorized actions.","exploitability":"Exploitation requires access to the FTM UI and the ability to manipulate network acknowledgement data. Precondition is an authenticated operator session.","blast_radius":"If exploited, the impact could include unauthorized payment actions and session hijacking, affecting operator-level access.","remediation":"Disable the NetworkAcknowledgement React component or upgrade to the latest version of IBM FTM for RedHat OpenShift.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["web","xss","auth","ui"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:49:48.689Z"}}