CVE-2026-15580
EUVD-2026-6397221.08.2026, 14:16
vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal browser extension: before 3.49.6.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| n-able | passportal | 𝑥 < 3.49.6 | CNA |
Common Weakness Enumeration
Vulnerability Media Exposure