CVE-2026-84388 is an improper restriction of rendered UI layers or frames vulnerability in all Fortinet FortiPAM Chrome Extension 8.0 and 7.4 releases. The extension could be induced by an arbitrary website to trust an attacker-controlled FortiPAM server and invoke privileged-session functionality without valid JWT authentication. The attacker-controlled session configuration could alter the browser proxy for the session, open an attacker-selected tab, and enable screen recording delivery to an attacker-controlled server. The extension consent control was exposed to the page’s main-world DOM, allowing a malicious page to programmatically approve it.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remotely exploitable, unauthenticated UI-layer/frame restriction flaw in Fortinet FortiPAM Chrome Extension versions 7.4 and 8.0 that may permit information disclosure. The listed CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L.
A critical (CVSS 9.1) improper-authentication vulnerability in the Fortinet Privileged Access Agent Chrome extension that can allow a remote unauthenticated attacker to proxy browser traffic after a user visits a malicious site.
A CVSS 9.1 vulnerability in Fortinet's FortiPAM Chrome extension that allows any website to change the browser session proxy, open a tab, and exfiltrate screen recordings of that tab to an attacker-controlled server. The described impact enables low-friction phishing and exposure of sensitive content viewed in attacker-opened tabs.
A critical vulnerability in the FortiPAM Chrome extension that lets arbitrary websites become a trusted FortiPAM server, launch an unauthenticated privileged-session workflow, automatically approve consent, and supply attacker-controlled configuration to set a proxy, open tabs, and exfiltrate screen recordings.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.