PT-2026-79374 · Unknown · Passportal

CVE-2026-15580

·

Published

2026-08-20

·

Updated

2026-08-21

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions PassPortal browser extension versions prior to 3.49.6
Description An unvalidated postMessage vulnerability in the PassPortal browser extension allows for authentication abuse. This flaw enables any website or iframe viewed by a user to obtain complete and persisted access to the decrypted vault for a duration of up to 100 days. Approximately 73,000 weekly active users were potentially affected.
Recommendations Update the PassPortal browser extension to version 3.49.6 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15580

Affected Products

Passportal