---
id: CVE-2026-15580
title: >-
  vault token disclosure via unvalidated postMessage vulnerability in N-able
  PassPortal allows Authentication Abuse.


  This issue affects the PassPortal browser extension: before 3.49.6.
summary: >-
  vault token disclosure via unvalidated postMessage vulnerability in N-able
  PassPortal allows Authentication Abuse.


  This issue affects the PassPortal browser extension: before 3.49.6.
severity: none
cwe:
  - CWE-1385
published: '2026-08-21'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:16:41.410'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15580'
references:
  - url: >-
      https://me.n-able.com/s/security-advisory/aArVy0000002GQTKA2/cve202615580-vault-token-disclosure-via-unvalidated-postmessage
    label: a5532a13-c4dd-4202-bef1-e0b8f2f8d12b
tags:
  - nvd
epss: 0.0019
epssPercentile: 0.0888
ingestedAt: '2026-09-08T20:10:03.157Z'
---

## Overview

vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse.

This issue affects the PassPortal browser extension: before 3.49.6.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
