CVE-2026-15580
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
21/08/2026
Last modified:
21/08/2026
Description
vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse.<br />
<br />
This issue affects the PassPortal browser extension: before 3.49.6.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM


