vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse.
This issue affects the PassPortal browser extension: before 3.49.6.
This issue affects the PassPortal browser extension: before 3.49.6.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 21 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal browser extension: before 3.49.6. | |
| Title | PassPortal browser extension: vault token disclosure via unvalidated postMessage | |
| Weaknesses | CWE-1385 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: N-able
Published:
Updated: 2026-08-21T15:07:33.739Z
Reserved: 2026-07-13T10:21:53.607Z
Link: CVE-2026-15580
No data.
Status : Received
Published: 2026-08-21T14:16:48.587
Modified: 2026-08-21T14:16:48.587
Link: CVE-2026-15580
No data.
OpenCVE Enrichment
Updated: 2026-08-21T15:30:05Z
Weaknesses