CVE-2026-15580EPSS p7.8%

CVE-2026-15580CVE-2026-15580

Description

vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal browser extension: before 3.49.6.

Scoring

EPSS0.19% probability of exploitation · percentile 7.8% · 2026-10-05T12:00:23Z
Last modified2026-09-08
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.