logo

N-able Bug Exposes Password Vault Master Keys

ID: 2b386387-5e8d-5608-8de0-8ffe804675ab

STIX ID: report--2b386387-5e8d-5608-8de0-8ffe804675ab

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-08-20

Date Updated: 2026-08-21

Author: Nate Nelson

...
...

A researcher discovered that the Passportal browser extension trusted window.postMessage calls from any website or iframe, allowing malicious sites to obtain access and refresh tokens that enable theft of all stored credentials and TOTPs from customer vaults; N-able patched the extension to verify request origin, but the product still decrypts data server-side (no E2EE), raising ongoing supply-chain and large-scale compromise concerns for MSPs and their downstream clients.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.