Executive brief
Fortinet's Chrome extension for privileged access management contains an authentication vulnerability that allows remote attackers to intercept and proxy a user's browser traffic without authentication. An attacker can exploit this by hosting a malicious website; when a user with the vulnerable extension visits it, their traffic can be routed through attacker-controlled servers, exposing credentials and sensitive data.
Technical details
The vulnerability is an improper authentication flaw (CWE-287) in the Fortinet Privileged Access Agent Chrome Extension's GUI component. A remote, unauthenticated attacker can trick a user into visiting a malicious website to proxy that user's browser traffic through attacker-controlled servers, resulting in information disclosure of credentials and session data. Fixes are available: version 8.0.1.123 or above for extension 8.0, coordinated with FortiPAM server upgrades to 1.9.1 or 1.8.4.
Affected products
- Fortinet FortiPAM Chrome Extension 7.4 all versions, 8.0 all versions
- Fortinet FortiPAM 1.8.x, 1.9.0
Timeline
- 2026-09-08: disclosed
- 2026-09-22: advisory