FortiPAM Chrome Extension leaks credentials (CVE-2026-84388) [PoC]
CVE-2026-84388
CVE-2026-84388: FortiPAM Chrome Extension 8.0 and 7.4 (CVSS 9.6) lets a remote attacker disclose privileged session data. Update to the fixed extension build.
Exploitation confirmed - public proof-of-concept - CVE-2026-84388 is a critical UI layer restriction flaw in Fortinet FortiPAM Chrome Extension 8.0 (all versions) and 7.4 (all versions) that lets a remote, unauthenticated attacker disclose sensitive information rendered in privileged browser sessions. No vendor patch has been confirmed for the affected branches; treat every deployed extension as exposed until Fortinet publishes fixed builds.
Overview
FortiPAM is Fortinet’s Privileged Access Management product, and its Chrome Extension injects session controls into privileged web sessions that administrators open through the platform. CVE-2026-84388 is a UI layer restriction weakness (CWE-1021 family): the extension fails to reliably enforce which frame or rendered layer sits on top of the content it protects.
Because the restriction is missing, an attacker who controls a remote page can render their own layer or frame over the protected interface. The victim sees what looks like the legitimate privileged session, while their clicks, keystrokes, or displayed credentials pass through attacker-controlled content. No authentication is required on the attacker’s side, but the attack needs the victim to interact with the crafted page while the extension is active.
Impact
The result is information disclosure in the worst possible context: a privileged session. Depending on how the overlay is constructed, an attacker can capture session tokens, harvested credentials displayed by FortiPAM, or actions the administrator believes they are performing inside a trusted console. CVSS scores the flaw 9.6 (network vector, low complexity, no privileges, user interaction required), which reflects both the ease of delivery and the value of the target: a session that by definition holds elevated access.
Remediation and Mitigation
- Remove or disable the FortiPAM Chrome Extension on 8.0 and 7.4 until Fortinet ships a fixed build, then upgrade to that version only.
- Watch Fortinet’s PSIRT advisory page for the patched extension version and cross-check the Chrome Web Store build number before redeploying.
- If the extension is business-critical, restrict privileged FortiPAM sessions to a managed browser profile with no general web browsing, which removes the attacker’s delivery path.
- Enable FortiPAM session recording and review recent privileged sessions for unexpected overlays, unexplained credential prompts, or anomalous click patterns.
- Treat credentials used in any session that showed suspicious rendering as compromised and rotate them.
For broader context on how browser-layer flaws are being weaponized this year, see our coverage of the Chrome V8 zero-day CVE-2026-11645 and the CISA KEV additions for Cisco and Chrome.
Security Insight
PAM vendors spend years hardening the server side of privileged access, then ship a browser extension that inherits the entire trust model of the web. This bug is a structural problem, not an isolated coding slip: any extension that overlays privileged content is one missing frame boundary away from being a phishing kit with a certificate. Compare it to the pattern in our weekly roundup of Ivanti and Chrome zero-days, where the weakest link repeatedly turns out to be privileged tooling running inside a general-purpose browser.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Public PoC References
Unverified third-party code
These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).
Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.
| Repository | Stars |
|---|---|
| ShadowForge-Cyber/CVE-2026-84388-POC Improper Restriction of Rendered UI Layers or Frames (CWE-1021) | ★ 0 |
Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.
Related Advisories
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server....
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may ...
When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauth...
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication ...