Critical SEVERITY — Vulnerability

Improper Authentication of FortiPAM Server

CVSSv3 Score: 9.1 An improper authentication vulnerability in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser traffic through attacker controlled servers if the user visits a malicious website. Revised on 2026-09-08 00:00:00

Platform
FortiGate / FortiOS
CVSS Score
9.1/10
Advisory
FG-IR-26-168
Published
08 September 2026
Views
35
Primary source: Review the official advisory at fortiguard.fortinet.com Go to Source

Summary

CVSSv3 Score: 9.1 An improper authentication vulnerability in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser traffic through attacker controlled servers if the user visits a malicious website. Revised on 2026-09-08 00:00:00

Source

FortiGate / FortiOS — Related Advisories

VIEW ALL →