Executive brief
Fortra File Integrity Monitoring (formerly Tripwire Enterprise) is a security tool used to track changes to critical system files and ensure compliance. A vulnerability in the user import process can cause new users to be granted higher access levels than intended. This could allow an administrator to inadvertently grant excessive permissions, potentially leading to unauthorized system modifications.
Technical details
A privilege assignment vulnerability (CWE-266) exists in Fortra File Integrity Monitoring (FIM) versions prior to 9.4.0. The issue occurs when the 'tetool import' command is used while the FIM service is running, specifically when the import process involves creating or modifying roles and their associated permissions. An attacker with high-level local privileges could exploit this behavior to gain elevated effective permissions that exceed their intended authorization. The vulnerability is addressed in version 9.4.0.
Affected products
- Fortra File Integrity Monitoring (FIM) / Tripwire Enterprise versions prior to 9.4.0
Timeline
- 2026-06-23: advisory: NVD publication date