CyberRota Analysis
AI-GeneratedThe N-able PassPortal browser extension versions prior to 3.49.6 are vulnerable to an unvalidated postMessage flaw that can lead to the disclosure of vault tokens, enabling potential authentication abuse. Organizations using this extension should prioritize patching to mitigate the risk of unauthorized access to sensitive information. This vulnerability poses a medium severity threat, particularly for users managing critical credentials through the affected extension.
CVE
CVE-2026-15580
Severity
MEDIUM
CVSS
6.9
EPSS
0.19%
Original NVD Description
vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal browser extension: before 3.49.6.