CVE-2026-15580
Received
Received - Intake
Token Disclosure via Unvalidated postMessage in N-able PassPortal
Vulnerability report for CVE-2026-15580, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-21
Last updated on: 2026-08-21
Assigner: N-able
Description
Description
vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse.
This issue affects the PassPortal browser extension: before 3.49.6.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| n-able | passportal | to 3.49.6 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1385 | The product uses a WebSocket, but it does not properly verify that the source of data or communication is valid. |