{"id":"CVE-2026-84388","published":"2026-09-22T15:17:18.950","lastModified":"2026-09-27T00:16:35.007","description":"A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack","cvssScore":9.6,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L","cwes":["CWE-1021"],"vendors":[],"products":[],"references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-168","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows an attacker to disclose information via a remote unauthenticated attack on Fortinet FortiPAM Chrome Extension versions 8.0 and 7.4, due to improper restriction of rendered UI layers or frames.","exploitability":"Exploitation is relatively easy given the remote unauthenticated nature, requiring only a browser with the extension installed.","blast_radius":"If exploited, the attacker could gain sensitive information, potentially leading to data breaches or further attacks.","remediation":"Disable the FortiPAM Chrome Extension until a patched version is available.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["info-disclosure","remote","browser","extension"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:53:32.311Z"}}