CVE-2026-15580CWE-1385

CVE-2026-15580

published August 21, 2026

CVSS
6.9
EPSS
0%
Percentile
8.6
In the wild
Unconfirmed
What it is

vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse.

This issue affects the PassPortal browser extension: before 3.49.6.

The record
Technical detail
CVSS
6.9 · NONE
CVSS v4.0
6.9 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00190 · 8.6th percentile
Weakness
CWE-1385 · Missing Origin Validation in WebSockets
Published
2026-08-21T18:16Z
References (1)
EPSS history
Timeline
  • 21 AUG 14:00Z
    PassPortal browser extension: vault token disclosure via unvalidated postMessage
    cvelistv5