Improper Authentication of FortiPAM Server
Fortinet discloses CVSS 9.1 improper authentication in FortiPAM's Chrome extension allowing unauthenticated attackers to proxy victims' browser traffic.
Fortinet advisory FG-IR-26-168 describes an improper authentication vulnerability (CWE-287) rated 9.1 in the Fortinet Privileged Access Agent Chrome Extension. A remote unauthenticated attacker could proxy a user's browser traffic through attacker-controlled servers if the user visits a malicious website. The advisory was revised on September 8, 2026.