Sceawere
Vulnerability Detail
CVE-2026-84388UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
FortiPAM UI Redressing Information Disclosure
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.6
- Creation Date
- 3h ago
- Vendor
- Fortinet
- Product
- FortiPAM Chrome Extension
- Attack Type
- Information disclosure
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.6",
"pubDate": "2026-09-22T15:17:18.950Z",
"pubdate": "2026-09-22T15:17:18.950Z",
"executiveSummary": "This vulnerability involves an improper restriction of rendered UI layers or frames within the FortiPAM Chrome Extension, categorized as an information disclosure flaw.\nThe vulnerability affects all versions of the FortiPAM Chrome Extension in the 8.0 and 7.4 release branches.\nThe flaw allows a remote, unauthenticated attacker to potentially access sensitive information by manipulating how the extension renders its interface.\nBy leveraging UI redressing techniques, an attacker can trick the extension into displaying or leaking information to an unauthorized context.\nThis poses a significant risk to the integrity and confidentiality of data managed by the FortiPAM extension, as the vulnerability does not require prior authentication from the attacker.\nSuccessful exploitation depends on the ability of the attacker to induce a user to interact with a malicious or compromised web environment that interacts with the vulnerable extension.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient enforcement of UI security boundaries within the FortiPAM Chrome Extension. The extension fails to properly restrict or validate the layering and framing of its UI components, making it susceptible to UI redressing or clickjacking-style attacks that bypass standard security constraints.\nIn the context of a browser extension, such vulnerabilities often arise when the extension's background script or popup interface does not explicitly define 'frame-ancestors' or equivalent Content Security Policy (CSP) directives for its internal pages. This allows external, malicious sites to embed the extension's UI components within an iframe or overlay elements atop them, effectively hijacking the user's interaction or observing rendered sensitive data.\nThe attack flow begins when an unauthenticated attacker hosts a malicious web page designed to target the FortiPAM extension. When a user with the extension installed navigates to this page, the malicious site leverages the lack of UI layer restrictions to render the extension's interface within an iframe or an overlay. By manipulating the CSS properties—such as opacity or z-index—the attacker can make the extension's UI elements appear transparent or invisible while still receiving input or leaking information rendered by the extension.\nBecause the vulnerability allows for unauthorized access to rendered information, the attacker can extract data that the extension is intended to keep private, such as credentials, session identifiers, or sensitive configuration details stored or processed by the extension. This information is then exfiltrated to the attacker's command-and-control server.\nThe vulnerable component is the rendering engine of the FortiPAM Chrome Extension itself, specifically how it manages cross-origin frames and DOM layering. Because this vulnerability is present in the extension's rendering logic, it is inherently exposed to any web page the user visits if the extension is active. No user authentication is required to initiate the attack, as the exploitation vector is external to the FortiPAM authentication flow, focusing instead on the client-side rendering behavior within the browser environment."
}