CVE-2026-84388 - Fortinet FortiPAM Chrome Extension

Improper authentication in the Fortinet FortiPAM privileged-access Chrome extension (the Privileged Access Agent).

Summary

A malicious website could register itself as a trusted FortiPAM server and invoke the privileged-access extension without valid JWT authentication. A remote, unauthenticated attacker could then supply a malicious privileged-session configuration that changed the browser proxy, opened an attacker-selected tab, auto-approved the extension's consent prompt, and streamed a recording of that tab to an attacker-controlled server.

Impact

The extension facilitates privileged-access sessions, so credentials, API keys and other data shown in the affected tabs are at risk. CVSS 9.1 (critical). No confirmed in-the-wild exploitation was reported.

Remediation

Upgrade FortiPAM to 1.9.1 or 1.8.4, and ensure the Chrome extension is version 8.0.1.123 or above. See Fortinet advisory FG-IR-26-168.