Medium severityNVD Advisory· Published Aug 21, 2026· Updated Aug 21, 2026
CVE-2026-15580
CVE-2026-15580
Description
vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse.
This issue affects the PassPortal browser extension: before 3.49.6.
Affected products
1- Range: <3.49.6
Patches
Vulnerability mechanics
References
1News mentions
1- Critical N-able Passportal Flaw Lets Malicious Websites Steal Entire Password Vault and 2FA CodesCyber Security News · Aug 21, 2026