CVE-2026-12163: Stored XSS in Fortra File Integrity Monitoring (FIM)
Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-site scripting (XSS) vulnerability in the Asset View UI component. An authenticated user with sufficient privileges to create or modify affected node or database configuration fields could store script content that may be rendered as HTML instead of safely escaped text when the affected Asset View UI content is displayed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortra File Integrity Monitoring (FIM) (formerly Tripwire Enterprise)to a version that resolves this vulnerability.Fixed in 9.4.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12163?
The severity of CVE-2026-12163 is medium with a score of 5.5.
How do I fix CVE-2026-12163?
To fix CVE-2026-12163, upgrade Fortra File Integrity Monitoring (FIM) to version 9.4.0.1 or later.
What type of vulnerability is CVE-2026-12163?
CVE-2026-12163 is a stored cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-12163?
Authenticated users with sufficient privileges in Fortra File Integrity Monitoring (FIM) prior to version 9.4.0.1 are affected by CVE-2026-12163.
What components of the software are impacted by CVE-2026-12163?
CVE-2026-12163 impacts the Asset View UI component of Fortra File Integrity Monitoring (FIM).