---
id: CVE-2026-84388
title: >-
  A improper restriction of rendered ui layers or frames vulnerability in
  Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension
  7.4 all versions may allow attacker to information disclosure via remote
  unauthenticat…
summary: >-
  A improper restriction of rendered ui layers or frames vulnerability in
  Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension
  7.4 all versions may allow attacker to information disclosure via remote
  unauthenticat…
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L'
cwe:
  - CWE-1021
vendor: Fortinet
product: FortiPAM Chrome Extension
affected:
  - fortipam_chrome_extension 8.0.1
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:09:58.680'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84388'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-26-168'
    label: psirt@fortinet.com
tags:
  - nvd
  - cve.org
  - exploit-available
scores:
  nvd: 9.6
  cna: 9.1
ingestedAt: '2026-09-22T15:05:01.090Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/ShadowForge-Cyber/CVE-2026-84388-POC'
  checkedAt: '2026-09-25T08:21:17.697Z'
exploitAvailable: true
epss: 0.00377
epssPercentile: 0.28869
---

## Overview

A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
