• PoC PUBLIC

CVE-2026-84388: information disclosure in Fortinet FortiPAM Chrome Extension

Remote attackers can extract sensitive data from the FortiPAM Chrome Extension; CVE-2026-84388 arises from improper restrictions on rendered UI layers or frames that expose information. The extension build identified as 8.0.1 is listed as affected. An attacker can reach the vulnerable extension over the network without needing FortiPAM credentials, but successful exploitation requires a user interaction (per the vulnerability’s UI:R vector).

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.6CRITICAL
EPSS
0.00377
CWE
CWE-1021
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as high priority: public exploit code exists and no fixed release is listed for the affected 8.0.1 build, so immediately block or limit the extension and apply compensating controls until Fortinet issues a patch.

What is CVE-2026-84388?

Remote attackers can extract sensitive data from the FortiPAM Chrome Extension; CVE-2026-84388 arises from improper restrictions on rendered UI layers or frames that expose information. The extension build identified as 8.0.1 is listed as affected. An attacker can reach the vulnerable extension over the network without needing FortiPAM credentials, but successful exploitation requires a user interaction (per the vulnerability’s UI:R vector).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L

Which versions of Fortinet FortiPAM Chrome Extension are affected?

BRANCHAFFECTEDFIXED
8.x8.0.1

Is CVE-2026-84388 being exploited?

Public exploit code is available.

How to fix CVE-2026-84388

  1. Disable or remove the FortiPAM Chrome Extension from managed browsers until a vendor fix is released.
  2. Enforce browser extension allowlists or use enterprise policies to prevent installation of the FortiPAM Chrome Extension.
  3. Restrict network exposure to FortiPAM-related services and monitor browser and application logs for exploitation attempts.
  4. Follow Fortinet guidance and install updates as soon as Fortinet publishes a fixed release.

Frequently asked questions

Is CVE-2026-84388 being actively exploited?

Public exploit code is available for CVE-2026-84388, indicating an elevated risk of active exploitation.

Which FortiPAM Chrome Extension versions are affected by CVE-2026-84388?

The provided facts list the FortiPAM Chrome Extension build 8.0.1 as affected.

Is there a patch for CVE-2026-84388?

No fixed version is listed in the supplied data; a patch is not shown for the affected 8.0.1 release.

Does CVE-2026-84388 require authentication?

CVE-2026-84388 can be triggered without FortiPAM account credentials, though exploitation requires user interaction.

References