CVE-2026-15580None▾ Sunlitvault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal browser extension: before 3.49.6.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse.
This issue affects the PassPortal browser extension: before 3.49.6.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54565Medium· 4.7rhwp is an HWP viewer and editor implemented in Rust and WebAssembly
CVE-2026-13272Medium· 5.4IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.
CVE-2026-18251Medium· 4.3IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin.
CVE-2026-88061Medium· 5.8career-ops is an open-source AI-assisted job search and application management tool
CVE-2026-71416High· 8.8Headroom compresses data before the data reaches a large language model
CVE-2026-85183Critical· 9.3Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications