CVE-2026-84388 PUBLISHED

Assigner: fortinet
Reserved: 01.09.2026 Published: 22.09.2026 Updated: 22.09.2026

A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L/E:P/RL:O/RC:C
CVSS Score: 9.1

Product Status

Vendor Fortinet
Product FortiPAM Chrome Extension
Versions Default: unaffected
  • Version 8.0.1 is affected

Solutions

Please refer to the Fortinet advisory for mitigation details.

References

Problem Types

  • Information disclosure CWE