Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3344 articles · 210946 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-15580PATCHED
n-able · passportal

PassPortal browser extension: vault token disclosure via unvalidated postMessage

Description

vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal browser extension: before 3.49.6.

Affected Products

VendorProductVersions
n-ablepassportal0

References

  • https://me.n-able.com/s/security-advisory/aArVy0000002GQTKA2/cve202615580-vault-token-disclosure-via-unvalidated-postmessage

Related News (1 articles)

Tier C
VulDB17d ago
CVE-2026-15580 | N-able PassPortal Extension 3.29.2 information disclosure
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV❌ No
Actively exploited❌ No
Patch available
3.49.6
CWECWE-1385
PublishedAug 21, 2026
Trending Score2
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-86218EXPKEV
pre-authentication remote code execution
Trending: 114
NONECVE-2026-86206
Access control filter bypass allows unauthorised access to APIs
Trending: 35
NONECVE-2026-86207
Authentication bypass leads to unauthorised access to N-central
Trending: 35
NONECVE-2026-18577
Incomplete patch leads to administrative account takeover
Trending: 2
NONECVE-2026-18556
Unauthenticated administrative account takeover
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 21, 2026
Discovered by ZDM
Aug 21, 2026
Patch Available
Aug 21, 2026