CVE-2026-12164: Privilege Escalation in Fortra File Integrity Monitoring (FIM)
Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or elevated effective permissions to users created by the tetool import command while FIM is running, particularly when the import also creates or changes roles or role-permission relationships.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortra File Integrity Monitoring (FIM) (formerly Tripwire Enterprise)to a version that resolves this vulnerability.Fixed in 9.4.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12164?
CVE-2026-12164 has a medium severity rating of 4.9.
What is the risk associated with CVE-2026-12164?
CVE-2026-12164 carries a risk score of 30.
How do I fix CVE-2026-12164?
To fix CVE-2026-12164, upgrade Fortra File Integrity Monitoring (FIM) to version 9.4.0 or later.
What kind of vulnerability is CVE-2026-12164?
CVE-2026-12164 is a privilege escalation vulnerability in Fortra File Integrity Monitoring.
Which versions of Fortra File Integrity Monitoring are affected by CVE-2026-12164?
CVE-2026-12164 affects versions of Fortra File Integrity Monitoring prior to 9.4.0.