Critical N-able Passportal Bug Lets Malicious Sites Access Password Vaults
Brief
N-able has patched a critical vulnerability in its Passportal browser extension that could have allowed any malicious website or embedded iframe to steal long-lived authentication tokens and gain persistent access to a victim’s decrypted password vault.
The flaw, tracked as CVE-2026-15580, affected Passportal extension version 3.
- 5 on Google Chrome and Microsoft Edge. N-able released version 3.
- 6 within 24 hours of receiving the report, closing an issue rated CVSS v4. 0 9.
- The extension reportedly has more than 73,000 weekly active users. Passportal is a cloud-based password and documentation-management platform built for managed service providers and IT teams.
