Executive brief
N-able PassPortal is a browser extension used for credential management and authentication. A vulnerability in its postMessage handling allows attackers to intercept and disclose vault tokens, potentially enabling unauthorized access to stored credentials and accounts.
Technical details
The vulnerability is a vault token disclosure issue arising from insufficient validation of postMessage communications in the PassPortal browser extension. An attacker can exploit unvalidated postMessage calls to intercept authentication tokens stored in the vault. The attack requires interaction with or hosting of a malicious webpage that the user visits while the extension is active. Successful exploitation allows token theft and subsequent authentication abuse to access protected resources. The issue affects PassPortal versions before 3.49.6 and is patched in that release.
Affected products
- N-able PassPortal before 3.49.6
Timeline
- 2026-08-21: disclosed