Improper Authentication of FortiPAM Server

🚨SEVERITY: CRITICAL — CVSS 9.1Security Advisory

TL;DR 📌

  • CVSSv3 Score: 9.1 An improper authentication vulnerability [CWE-287] in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user’s browser traffic through attacker controlled servers if the user visits a malicious website. Revised on 2026-09-08 00:00:00
  • Highest CVSS: 9.1 (Critical).
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.

What it is

Fortinet has published an advisory for an improper authentication weakness (CWE-287) in the Fortinet Privileged Access Agent Chrome Extension, the browser component associated with FortiPAM. The flaw carries a CVSS score of 9.1, rated critical.

The issue allows a remote, unauthenticated attacker to proxy a user’s browser traffic through attacker-controlled servers. The trigger is a user visiting a malicious website; no credentials or prior access to the FortiPAM environment are needed on the attacker’s side. Because the extension is what mediates privileged access sessions in the browser, an attacker who can insert themselves into that traffic path gains visibility into, and potential control over, the user’s browsing session as it relates to privileged access.

This sits in the client-side data plane — the extension running in the user’s browser — rather than in FortiPAM’s server-side management interface. The attack depends on the user’s browser reaching a malicious site while the extension is active; it is not a direct network attack against the FortiPAM server itself.

No CVE identifier has yet been assigned in the advisory, and Fortinet has not published fixed version information at this time. The advisory should be consulted directly for updates on both points.

What to do

  • Track FG-IR-26-168 directly for the CVE assignment and fixed release information, as neither is available yet.
  • Inventory where the Fortinet Privileged Access Agent Chrome Extension is deployed, since this is a client-side component that may not be captured by server or appliance asset inventories.
  • Until a fix is published, treat the extension as a higher-risk target for browser-based attacks and reinforce standard web-browsing hygiene for users who have it installed (URL filtering, DNS filtering, and browser isolation where available).
  • Once Fortinet issues a fixed version, prioritise updating the extension across all endpoints where it is installed, given the 9.1 severity rating.
  • Do not wait for a CISA KEV listing before acting — none is recorded for this issue at present, but the absence of a listing does not indicate the flaw is unreachable.

For leadership 🧭

Executive summary. A critical flaw in the Fortinet Privileged Access Agent Chrome Extension lets an attacker hijack a privileged user’s browser traffic simply by getting them to visit a malicious website, no credentials required. No fix or CVE exists yet, so affected organisations should inventory and restrict exposure now rather than wait for a patch.

Why it matters:

  • The flaw sits in the Chrome extension that mediates FortiPAM privileged access sessions, not the FortiPAM server, so it won’t show up in server or appliance vulnerability scans.
  • A remote, unauthenticated attacker only needs the user to browse to a malicious site to proxy that user’s browser traffic through attacker-controlled infrastructure.
  • Because the extension handles privileged access sessions, an attacker on that traffic path could gain visibility into, or influence over, privileged session activity.
  • No CVE, patched version, or KEV listing exists yet, leaving affected organisations with only compensating controls until Fortinet publishes a fix.

Now / Next / Later:

  • Now: Identify every endpoint where the Fortinet Privileged Access Agent Chrome Extension is installed, since this client-side component is easy to miss in server-focused asset inventories.
  • Next: Apply URL filtering, DNS filtering, and browser isolation where available for users running the extension, and monitor FG-IR-26-168 for the CVE assignment and fixed release.
  • Later: Once Fortinet ships a fixed version, roll it out across all endpoints running the extension as a priority given the 9.1 severity, and add browser extensions used for privileged access to standard patch-tracking processes.

Source