Skip to content

CVE-2026-84388

FortiPAM Chrome Extension improper authentication lets malicious sites proxy browser traffic (CVE-2026-84388)

Critical 9.1 Vendor: Fortinet Published

Fortinet advisory FG-IR-26-168 covers CVE-2026-84388, an improper authentication weakness in the FortiPAM Chrome Extension. A malicious website could proxy a user's browser traffic through attacker-controlled servers. No fixed version or workaround has been published.

What happened

Fortinet describes an improper authentication weakness in the FortiPAM Chrome Extension. The weakness is reachable over the network with low attack complexity and no prior authentication, but it requires a user of the affected extension to visit a malicious website. If that happens, a remote unauthenticated attacker may be able to proxy the user's browser traffic through attacker-controlled servers, which creates the potential for unauthorised disclosure or modification of information in the affected session. The CVSS v3.1 score is 9.1 (Critical).

Fortinet has not said that this issue is exploited or publicly disclosed, and it is not listed in CISA KEV. No fixed release is listed in Fortinet's advisory at this time.

Who is affected

Fortinet lists FortiPAM Chrome Extension 8.0.1 as affected in the advisory. The CVE record also states that all versions of the FortiPAM Chrome Extension 8.0 and 7.4 lines are affected. The extension is part of FortiPAM privileged access management deployments, so installations used by administrators and other privileged users should be checked first.

What to do now

Fortinet has not published a fixed version or workaround for CVE-2026-84388 in FG-IR-26-168. No patch has been released at the date of this advisory. Until that changes, treat this as an unpatched browser-side weakness and contain it.

  1. Identify installations of the FortiPAM Chrome Extension, especially version 8.0.1 and other 8.0 or 7.4 line versions described in the CVE record.
  2. Restrict use of the extension to trusted internal portals. Where it is not required, disable or remove it. This reduces the browser surface the flaw relies on.
  3. Remind privileged users not to use the extension while browsing external or untrusted sites.
  4. Monitor Fortinet's FG-IR-26-168 advisory for changes; do not assume a fixed version exists until Fortinet publishes one.

How to detect it

Fortinet has not published detection guidance or indicators of compromise for this issue. Because the described behaviour is proxying of browser traffic, have support teams review the affected extension's settings and browser proxy configuration for unexpected endpoints after any suspicious browsing, and investigate traffic to unfamiliar proxy hosts.

Beyond the patch

This is a browser-delivered risk as much as an extension flaw: one privileged user visiting a malicious page is enough to redirect browser traffic to attacker-controlled infrastructure. Managed Cyber Awareness Training and Digital Risk Protection are relevant here because open redirects and UI redress are phishing enablers, and they help reduce the likelihood that a malicious page turns into a proxied session.

Affected and fixed versions

ProductAffectedFixed in
FortiPAM Chrome Extension8.0.1No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.