CVE-2026-12164 PUBLISHED

Privilege Escalation in Fortra File Integrity Monitoring (FIM)

Assigner: Fortra
Reserved: 12.06.2026 Published: 23.06.2026 Updated: 24.06.2026

Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or elevated effective permissions to users created by the tetool import command while FIM is running, particularly when the import also creates or changes roles or role-permission relationships.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 4.4

Product Status

Vendor Fortra
Product File Integrity Monitoring (FIM)
Versions Default: unaffected
  • affected from 0 to 9.4.0 (excl.)

Solutions

Upgrade to version 9.4.0 or later.

References

Problem Types

  • CWE-266 Incorrect privilege assignment CWE

Impacts

  • CAPEC-233 Privilege Escalation