Junglewise Threat Intelligence

CVE-2026-12163: Fortra File Integrity Monitoring stored XSS in Asset View UI

CVE-2026-12163 · Severity: medium · CVSS 5.5 · Published 2026-06-23

Vendors: Fortra.

Executive brief

Fortra File Integrity Monitoring (formerly Tripwire Enterprise) is used by organizations to track changes to critical system files and ensure security compliance. A vulnerability in the Asset View interface allows an authorized user with administrative-level permissions to inject malicious scripts into the system's configuration fields. If exploited, these scripts could execute in the browsers of other users, potentially leading to unauthorized actions or data access within the management console.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Asset View UI component of Fortra File Integrity Monitoring (FIM). The flaw is caused by improper neutralization of input during web page generation (CWE-79) within node or database configuration fields. An authenticated attacker with high privileges (PR:H) can inject malicious scripts into these fields. When another user views the affected Asset View UI, the application fails to safely escape the stored content, leading to script execution in the context of the victim's session. This vulnerability is addressed in version 9.4.0.1.

Affected products

  • Fortra File Integrity Monitoring (FIM) / Tripwire Enterprise prior to 9.4.0.1

Timeline

  • 2026-06-23: disclosed
  • 2026-06-23: advisory

References

Related threats