CVE 4.9 MEDIUM

Privilege Escalation in Fortra File Integrity Monitoring (FIM)_CVE-2026-12164

4.9 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Description

Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or elevated effective permissions to users created by the tetool import command while FIM is running, particularly when the import also creates or changes roles or role-permission relationships.

Basic Information

ID CVE-2026-12164
Source Fortra
Published Jun 23, 2026 at 22:15

Affected Product

Vendor Fortra
Product File Integrity Monitoring (FIM)
Affected Versions Fortra File Integrity Monitoring (FIM) 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.