ZeroHour
Fortinet PSIRTpublished ()ingested

Improper Authentication of FortiPAM Server

highAdvisoryimportance 45
AI summary · glm-5.3

Fortinet discloses CVSS 9.1 improper authentication in FortiPAM's Chrome extension allowing unauthenticated attackers to proxy victims' browser traffic.

Fortinet advisory FG-IR-26-168 describes an improper authentication vulnerability (CWE-287) rated 9.1 in the Fortinet Privileged Access Agent Chrome Extension. A remote unauthenticated attacker could proxy a user's browser traffic through attacker-controlled servers if the user visits a malicious website. The advisory was revised on September 8, 2026.

  • CVSS 9.1 improper authentication in FortiPAM Privileged Access Agent Chrome Extension
  • Malicious website visit could let attackers proxy victim browser traffic
Full article

CVSSv3 Score: 9.1 An improper authentication vulnerability [CWE-287] in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser traffic through attacker controlled servers if the user visits a malicious website. Revised on 2026-09-08 00:00:00

This source does not provide full text. Read it at fortiguard.fortinet.com.