CVE-2026-18872
9.3 CRITICALPublished 2026-09-23 · Updated 2026-09-23
AI risk analysis
- Summary
- The flaw allows a malicious actor to inject script into stored network acknowledgement data, leading to session hijacking and unauthorized actions.
- Exploitability
- Exploitation requires access to the FTM UI and the ability to manipulate network acknowledgement data. Precondition is an authenticated operator session.
- Blast radius
- If exploited, the impact could include unauthorized payment actions and session hijacking, affecting operator-level access.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Disable the NetworkAcknowledgement React component or upgrade to the latest version of IBM FTM for RedHat OpenShift.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator browsers, enabling session hijacking and unauthorized operator-level payment actions.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Weaknesses
CWE-79
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-71419PoC
- HIGHCVE-2026-16143
- MEDIUMCVE-2026-36468PoC
- CRITICALCVE-2026-59167PoC
- MEDIUMCVE-2026-59830PoC
- HIGHCVE-2026-63459PoC
- HIGHCVE-2026-71233PoC
- CRITICALCVE-2026-75684
Related by shared AI tags and CWE weakness class. Browse the full archive.