Junglewise Threat Intelligence

CVE-2026-18131: IBM Financial Transaction Manager cross-site scripting in web interface

CVE-2026-18131 · Severity: high · CVSS 8.2 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager (FTM) is a payment processing platform used for secure financial transactions on OpenShift. A vulnerability in the web interface allows an attacker to inject malicious JavaScript that executes in the browser of any authenticated user, potentially enabling account takeover, credential theft, or fraudulent transactions through actions performed on the victim's behalf.

Technical details

The vulnerability is a cross-site scripting (XSS) flaw caused by improper neutralization of HTML input in the web interface. An unauthenticated attacker can craft a malicious request that causes JavaScript to execute in the context of an authenticated user's session, achieving persistence across the application scope. The attack requires user interaction (clicking a link) but no prior authentication on the attacker's part.

Affected products

  • IBM Financial Transaction Manager 4.x and earlier

Timeline

  • 2026-09-22: disclosed

References

Related threats