External risk intelligence

Fortinet FortiPAM Chrome Extension Information Disclosure Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-84388

The vulnerability affects a browser extension. Browser extensions are client-side software components that execute within a user's local browser environment. They are not network services, gateways, or public-facing infrastructure, making internet-wide exposure or remote, unauthenticated network accessibility via the public internet fundamentally inapplicable to this component's deployment.

Information Disclosure

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This CVE involves a vulnerability in a browser extension that could potentially expose information. The main concern is confirming if your organization uses this specific extension.

  • Information exposure risk in browser extension.
  • Confirm if this technology is in use.
  • Understand potential exposure to sensitive data.

Attack Path

How an attacker could exploit the issue

An attacker could potentially trick a user into visiting a malicious website or opening a crafted document. This would cause the vulnerable FortiPAM Chrome Extension to display sensitive information.

  • Requires network access and no privileges.
  • User interaction through a browser is needed.
  • Leads to sensitive data exposure.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in the FortiPAM Chrome Extension could allow an attacker to disclose sensitive information through a remote, unauthenticated attack when a user interacts with a malicious site. This could expose data accessible by the extension within the user's browser session.

  • Extension data could be at risk.
  • User interaction with malicious sites.
  • Sensitive information disclosure may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the FortiPAM Chrome Extension is likely to impact users and potentially data accessed through that extension. Initial triage should focus on identifying all instances of the extension, assessing its reach within the organization, and confirming business criticality. The next practical move involves identifying the accountable owner, such as the platform or security team responsible for managing browser extensions, and then planning remediation based on the assessed risk.

  • Platform or security teams own this issue.
  • Verify extension presence and user impact.
  • Plan user communication and controlled rollout.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the FortiPAM Chrome Extension?

The FortiPAM Chrome Extension is a browser-based add-on designed to integrate with Fortinet’s Privileged Access Management platform. It enables users to securely manage and access privileged credentials or remote sessions directly from their web browser, streamlining workflows for authorized personnel who need to connect to protected internal infrastructure.

How does CVE-2026-84388 create a security risk?

This vulnerability is classified as CWE-1021, which refers to improper restriction of rendered UI layers or frames. In plain terms, the extension fails to properly isolate its interface from external websites. This weakness could allow a malicious site to manipulate the extension's visual elements, potentially tricking the software into disclosing sensitive information that the extension is authorized to handle.

Do I need to be logged into the extension to be at risk?

Yes. The vulnerability typically requires an active user session where the extension is running in the background. Simply installing the extension without an active session or without navigating to a specifically crafted malicious website generally does not trigger the underlying bug. The attack path relies on the user interacting with an external site while the extension is active in their browser.

Why is this CVE considered an external threat?

While Halo Surface Signal notes that this is a client-side browser component rather than a public-facing server, the vulnerability is classified as external because it relies on network-based triggers. An attacker exploits this by enticing a user to visit an internet-hosted malicious site. Even though the extension resides on your local machine, the trigger mechanism originates from outside your network perimeter.

What is the first step if I use this extension?

Your priority is to determine the scope of use within your organization. Identify which systems or user groups have this specific extension installed. Once you have an inventory, coordinate with your IT or security team to assess the data the extension can access and monitor for any vendor-provided updates or guidance on disabling the extension until a patch is applied.

References