CVE-2026-84388
45Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.1
from disclosure to weapon0 days
Published on NVDSep 22
1st PoCSep 22
exploitation probability
—
observed exploitation
nono source reports it
1 public exploit(s)
A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L/E:P/RL:O/RC:C
Affected products
Fortinet · FortiPAM Chrome Extensionpublic PoCs found — 1
githubgithub.com/ShadowForge-Cyber/CVE-2026-84388-POC★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.