Junglewise Threat Intelligence

CVE-2026-15580: N-able PassPortal vault token disclosure via unvalidated postMessage

CVE-2026-15580 · Severity: info · Published 2026-08-21

Vendors: N-able.

Executive brief

N-able PassPortal is a browser extension used for credential management and authentication. A vulnerability in its postMessage handling allows attackers to intercept and disclose vault tokens, potentially enabling unauthorized access to stored credentials and accounts.

Technical details

The vulnerability is a vault token disclosure issue arising from insufficient validation of postMessage communications in the PassPortal browser extension. An attacker can exploit unvalidated postMessage calls to intercept authentication tokens stored in the vault. The attack requires interaction with or hosting of a malicious webpage that the user visits while the extension is active. Successful exploitation allows token theft and subsequent authentication abuse to access protected resources. The issue affects PassPortal versions before 3.49.6 and is patched in that release.

Affected products

  • N-able PassPortal before 3.49.6

Timeline

  • 2026-08-21: disclosed

References