Skip to content
N-able Passportal Vulnerability Exposes User Credentials

N-able Passportal Vulnerability Exposes User Credentials

First seen 20 Aug 2026, 22:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 21, 2026 at 22:48 UTC
  • •N-able's Passportal vulnerability allows unauthorized access to user credentials.
  • •Approximately 73,000 users are affected, with a CVSS score of 9.4.
  • •N-able issued a patch within 24 hours of the vulnerability being reported.

A vulnerability in N-able's Passportal password manager allows any malicious website to gain complete access to user credentials for up to 100 days. The issue, identified by Bay Area Labs, stems from the browser extension's failure to validate the origin of messages, enabling attackers to exploit access tokens. The vulnerability affects approximately 73,000 weekly active users and has been assigned CVE-2026-15580. N-able patched the issue within 24 hours of being notified, but the design flaws raise ongoing security concerns. Users are advised to remain vigilant as the cloud-based architecture may still pose risks. The vulnerability was discovered on July 8, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2026-07-08
Vulnerability discovered in Passportal
Bay Area Labs found that Passportal's browser extension could be exploited by any website to access user credentials.
Darkreading
2026-07-08
N-able notified of the vulnerability
Bay Area Labs reported the vulnerability to N-able, prompting a swift response.
amibeingpwned.com
2026-07-09
Patch released by N-able
N-able published a fix for the vulnerability within 24 hours of being notified.
amibeingpwned.com

More articles in this cluster (2)

Following this threat?

Track CVE-2026-15580 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed