Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
N-able Passportal Vulnerability Allows Password Theft

N-able Passportal Vulnerability Allows Password Theft

Posted on August 22, 2026 By CWS

A significant security flaw in the N-able Passportal extensions for Chrome and Microsoft Edge has been identified, potentially enabling malicious websites to access an organization’s entire password vault and active two-factor authentication codes.

Details of the Vulnerability

The flaw, identified as CVE-2026-15580, received a critical CVSS v4.0 base score of 9.4. It affected version 3.49.5 of the Passportal extension. N-able addressed this issue by releasing version 3.49.6 within 24 hours of being informed of the vulnerability.

Passportal serves as a cloud-based platform for password and privileged access management, primarily utilized by managed service providers and IT teams for storing client credentials and sensitive documentation. The vulnerability was rooted in unsafe interactions between the content script and the extension’s iframe.

Mechanisms of Exploitation

The browser extension employed the window.postMessage mechanism for message exchanges but failed to validate the sender’s origin. Consequently, any website visited by a logged-in Passportal user could issue a request to access authentication tokens from the extension.

These tokens could be exploited beyond just filling in passwords automatically. Attackers could list vault entries, request decrypted passwords, acquire time-based one-time password codes, and maintain access using refresh tokens for up to 100 days. Such a breach could occur through compromised websites, malicious ads, or injected iframes.

N-able’s Response and Recommendations

N-able has implemented a patch that enhances the message-processing logic of the extensions by verifying that messages originate from the extension itself and validating trusted iframe sources, thus preventing unauthorized access to the extension’s messaging channel.

Organizations using N-able Passportal should ensure their browser extensions are updated to version 3.49.6 or later. Administrators are advised to review extension management policies, identify unmanaged browser installations, and consider resetting high-value credentials where potential exposure cannot be excluded.

Despite the fix for the token-leakage flaw, concerns about server-side decryption remain, as it involves cloud-side processing of sensitive functions of the password manager. Experts recommend transitioning to a client-side, end-to-end encryption model and using native browser extension messaging APIs instead of the exposed window.postMessage channels.

Organizations are encouraged to enhance their cybersecurity protocols promptly to prevent data breaches and ensure the integrity of their password management systems.

Cyber Security News Tags:browser extension, CVE-2026-15580, Cybersecurity, IT security, managed service providers, N-able, Passportal, password security, two-factor authentication, Vulnerability

Post navigation

Previous Post: US Bank Probes LockBit Ransomware Data Breach Allegations
Next Post: How AI Testing Breached a Company’s Security Systems

Related Posts

Hackers Allegedly Claim Breach of Mercedes-Benz USA Legal and Customer Data Hackers Allegedly Claim Breach of Mercedes-Benz USA Legal and Customer Data Cyber Security News
Threat Actors Weaponizing Facebook Ads to Deliver Malware and Stealing Wallet Passwords Threat Actors Weaponizing Facebook Ads to Deliver Malware and Stealing Wallet Passwords Cyber Security News
Multi-Stage Windows Malware Invokes PowerShell Downloader Using Text-based Payloads Using Remote Host Multi-Stage Windows Malware Invokes PowerShell Downloader Using Text-based Payloads Using Remote Host Cyber Security News
CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity Cyber Security News
North Korean Hackers Evade UN Sanctions Leveraging Cyber Capabilities, IT Workers and Crypto Activities North Korean Hackers Evade UN Sanctions Leveraging Cyber Capabilities, IT Workers and Crypto Activities Cyber Security News
Hackers Exploit GitHub Actions to Insert Miasma Malware Hackers Exploit GitHub Actions to Insert Miasma Malware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AppViewX Enhances AI Security with New Tools
  • Cyberattack Exposes Data of Over 1 Million in Arizona Courts
  • Criminal IP Unveils AITEM: Revolutionizing Cybersecurity
  • Iranian Hackers Exploit Fake Coding Test to Infiltrate Iraqi Systems
  • Aembit Enhances Security for AI Agents in Enterprises

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AppViewX Enhances AI Security with New Tools
  • Cyberattack Exposes Data of Over 1 Million in Arizona Courts
  • Criminal IP Unveils AITEM: Revolutionizing Cybersecurity
  • Iranian Hackers Exploit Fake Coding Test to Infiltrate Iraqi Systems
  • Aembit Enhances Security for AI Agents in Enterprises

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark