Stored Cross-Site Scripting Vulnerability in Fortra File Integrity Monitoring
CVE-2026-12163

5.5MEDIUM

Key Information:

Vendor

Fortra

Vendor
CVE Published:
23 June 2026

What is CVE-2026-12163?

Fortra File Integrity Monitoring (FIM), previously known as Tripwire Enterprise, is susceptible to a stored cross-site scripting vulnerability within its Asset View UI component. This flaw allows authenticated users with adequate privileges to input malicious script content into affected node or database configuration fields. If the vulnerable Asset View UI content is displayed, the stored scripts could be executed as HTML, posing a risk of unauthorized actions or information disclosure. Users are urged to upgrade to version 9.4.0.1 or later to mitigate this vulnerability.

Affected Version(s)

Fortra File Integrity Monitoring (FIM) 0 < 9.4.0.1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.