CVE-2026-84388
FortiPAM Chrome Extension improper authentication lets malicious sites proxy browser traffic (CVE-2026-84388)
Fortinet advisory FG-IR-26-168 covers CVE-2026-84388, an improper authentication weakness in the FortiPAM Chrome Extension. A malicious website could proxy a user's browser traffic through attacker-controlled servers. No fixed version or workaround has been published.
What happened
Fortinet describes an improper authentication weakness in the FortiPAM Chrome Extension. The weakness is reachable over the network with low attack complexity and no prior authentication, but it requires a user of the affected extension to visit a malicious website. If that happens, a remote unauthenticated attacker may be able to proxy the user's browser traffic through attacker-controlled servers, which creates the potential for unauthorised disclosure or modification of information in the affected session. The CVSS v3.1 score is 9.1 (Critical).
Fortinet has not said that this issue is exploited or publicly disclosed, and it is not listed in CISA KEV. No fixed release is listed in Fortinet's advisory at this time.
Who is affected
Fortinet lists FortiPAM Chrome Extension 8.0.1 as affected in the advisory. The CVE record also states that all versions of the FortiPAM Chrome Extension 8.0 and 7.4 lines are affected. The extension is part of FortiPAM privileged access management deployments, so installations used by administrators and other privileged users should be checked first.
What to do now
Fortinet has not published a fixed version or workaround for CVE-2026-84388 in FG-IR-26-168. No patch has been released at the date of this advisory. Until that changes, treat this as an unpatched browser-side weakness and contain it.
- Identify installations of the FortiPAM Chrome Extension, especially version 8.0.1 and other 8.0 or 7.4 line versions described in the CVE record.
- Restrict use of the extension to trusted internal portals. Where it is not required, disable or remove it. This reduces the browser surface the flaw relies on.
- Remind privileged users not to use the extension while browsing external or untrusted sites.
- Monitor Fortinet's FG-IR-26-168 advisory for changes; do not assume a fixed version exists until Fortinet publishes one.
How to detect it
Fortinet has not published detection guidance or indicators of compromise for this issue. Because the described behaviour is proxying of browser traffic, have support teams review the affected extension's settings and browser proxy configuration for unexpected endpoints after any suspicious browsing, and investigate traffic to unfamiliar proxy hosts.
Beyond the patch
This is a browser-delivered risk as much as an extension flaw: one privileged user visiting a malicious page is enough to redirect browser traffic to attacker-controlled infrastructure. Managed Cyber Awareness Training and Digital Risk Protection are relevant here because open redirects and UI redress are phishing enablers, and they help reduce the likelihood that a malicious page turns into a proxied session.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| FortiPAM Chrome Extension | 8.0.1 | No fixed version listed yet |