Description:
Forwarded from TWCERT/CC Security Advisory TWCERTCC-200-202609-00000013
Fortinet Privileged Access Agent Chrome Extension has an improper authentication vulnerability (CVE-2026-84388, CVSS: 9.1). If a user visits a malicious website, unauthenticated remote attackers may be able to control the browser traffic of users proxied by the server.
Affected Platforms:
Recommended Actions:
References:
-
Computer and Communication Center
Network System Division