← Back to search

CVE-2026-18872

9.3 CRITICAL

Published 2026-09-23 · Updated 2026-09-23

AI risk analysis

Summary
The flaw allows a malicious actor to inject script into stored network acknowledgement data, leading to session hijacking and unauthorized actions.
Exploitability
Exploitation requires access to the FTM UI and the ability to manipulate network acknowledgement data. Precondition is an authenticated operator session.
Blast radius
If exploited, the impact could include unauthorized payment actions and session hijacking, affecting operator-level access.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the NetworkAcknowledgement React component or upgrade to the latest version of IBM FTM for RedHat OpenShift.
webxssauthui

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator browsers, enabling session hijacking and unauthorized operator-level payment actions.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Weaknesses

CWE-79

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.