Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault Access
2 Articles
2 Articles
Critical N-able Passportal Flaw Lets Malicious Websites Steal Entire Password Vault and 2FA Codes
A critical vulnerability in N-able Passportal’s Chrome and Microsoft Edge browser extensions could allow a malicious website or embedded iframe to steal an organization’s entire password vault, including live two-factor authentication codes. Tracked as CVE-2026-15580, the issue received a CVSS v4.0 base score of 9.4 and affected Passportal extension version 3.49.5. N-able released version 3.49.6 to address the flaw within 24 hours of disclosure.…
Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault Access
Cybersecurity researchers have revealed a critical vulnerability in N-able’s PassPortal browser extension that could have allowed a malicious website or embedded iframe to obtain authentication materials and take control of a user’s password vault. This vulnerability, tracked as CVE-2026-15580, affects PassPortal version 3.49.5 and has a CVSS v4.0 base score of 9.4. It was patched […] This article has been indexed from GBHackers Security | #1 Gl…
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium






