← All Advisories

Fortinet FortiPAM Chrome Extension All 8.0 and 7.4 Versions Improperly Restricts Rendered UI Layers, Potentially Enabling Clickjacking Attacks Against Users of the PAM Interface

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-84388

Key Details

CVECVE-2026-84388
CVSS Score / Version9.6 (Critical) / CVSS v3.1
Updated2026-09-27
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is required; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is low.
Classified asCWE-1021 (Improper Restriction of Rendered UI Layers or Frames)

What to Know

A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-84388
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-84388