SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-15580

MEDIUM · CVSS 6.9 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The N-able PassPortal browser extension versions prior to 3.49.6 are vulnerable to an unvalidated postMessage flaw that can lead to the disclosure of vault tokens, enabling potential authentication abuse. Organizations using this extension should prioritize patching to mitigate the risk of unauthorized access to sensitive information. This vulnerability poses a medium severity threat, particularly for users managing critical credentials through the affected extension.

CVE
CVE-2026-15580
Severity
MEDIUM
CVSS
6.9
EPSS
0.19%

Original NVD Description

vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal browser extension: before 3.49.6.