By vendor
Fortra vulnerabilities
Known CVEs affecting Fortra products, prioritized by severity, with SEC.co remediation and detection guidance.
2 published vulnerabilities
- CVE-2026-12163MEDIUM 5.5
Fortra's File Integrity Monitoring (FIM) solution, previously known as Tripwire Enterprise, has a stored cross-site scripting (XSS) vulnerability affecting versions before 9.4.0.1. An authenticated insider with elevated privileges can inject malicious script into configuration fields that later execute in a user's browser when viewing the Asset View UI component. The vulnerability requires both authentication and privilege escalation, limiting immediate risk but posing a real threat in environments where privileged users may be compromised or act maliciously.
- CVE-2026-12164MEDIUM 4.4
Fortra File Integrity Monitoring (FIM), the integrity monitoring solution formerly known as Tripwire Enterprise, contains a permission assignment flaw in its user import functionality. When administrators use the tetool import command to add users while FIM is actively running—especially if the import simultaneously creates or modifies roles and their associated permissions—the system may grant those imported users incorrect or overly permissive access rights. This means a user intended to have limited monitoring privileges could end up with elevated capabilities, creating an unintended privilege escalation within the FIM system itself.