Junglewise Threat Intelligence

CVE-2026-84388: Fortinet FortiPAM Chrome Extension improper authentication flaw

CVE-2026-84388 · Severity: critical · CVSS 9.6 · Published 2026-09-22

Technologies: Fortinet Fortipam. Vendors: Fortinet.

Executive brief

Fortinet's Chrome extension for privileged access management contains an authentication vulnerability that allows remote attackers to intercept and proxy a user's browser traffic without authentication. An attacker can exploit this by hosting a malicious website; when a user with the vulnerable extension visits it, their traffic can be routed through attacker-controlled servers, exposing credentials and sensitive data.

Technical details

The vulnerability is an improper authentication flaw (CWE-287) in the Fortinet Privileged Access Agent Chrome Extension's GUI component. A remote, unauthenticated attacker can trick a user into visiting a malicious website to proxy that user's browser traffic through attacker-controlled servers, resulting in information disclosure of credentials and session data. Fixes are available: version 8.0.1.123 or above for extension 8.0, coordinated with FortiPAM server upgrades to 1.9.1 or 1.8.4.

Affected products

  • Fortinet FortiPAM Chrome Extension 7.4 all versions, 8.0 all versions
  • Fortinet FortiPAM 1.8.x, 1.9.0

Timeline

  • 2026-09-08: disclosed
  • 2026-09-22: advisory

References

Related threats