CVE-2026-84388

A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to informatio

Severity
Critical 9.1
CVSS 3.1
Exploited
Not listed
EPSS
0.004
31.7th percentile
Discovered by
Third party
Vendor advisory acknowledgement
Published
Sep 22, 2026
Assigned by fortinet

Description

A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack

Weakness: CWE-1021

Affected products

Vendor Product Category Matched by
Fortinet FortiPAM Identity / IAM / MFA cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiPAM Chrome Extension

Credit

Fortinet is pleased to thank Kevin Joensen from Baldur Security, Eric Brandel from Target, Dan Rosenqvist from Shelltrail, and James Arnott from Bay Area Labs (https://amibeingpwned.com/) for reporting this vulnerability under responsible disclosure.

Vendor remediation

Please refer to the Fortinet advisory for mitigation details.

Something wrong here?