CVE-2026-15580

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
21/08/2026
Last modified:
21/08/2026

Description

vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse.<br /> <br /> This issue affects the PassPortal browser extension: before 3.49.6.