CVE-2026-84388
A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to informatio
Description
A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack
Weakness: CWE-1021
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiPAM | Identity / IAM / MFA | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiPAM Chrome Extension
Credit
Fortinet is pleased to thank Kevin Joensen from Baldur Security, Eric Brandel from Target, Dan Rosenqvist from Shelltrail, and James Arnott from Bay Area Labs (https://amibeingpwned.com/) for reporting this vulnerability under responsible disclosure.
Vendor remediation
Please refer to the Fortinet advisory for mitigation details.