Security1 distinct publisher2 min readPublished
A missing origin check let any site pull an MSP's decrypted vault and keep access for up to 100 days, according to the researchers who found it. Installing the patch does not retire tokens already taken.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Rotation, not a version bump, is what the 100-day figure asks for. The leak happened in the browser; the tokens are honoured by N-able's servers. An attacker who harvested an access and refresh pair from a victim running v3.49.5 does not care that the victim now runs v3.49.6, and the disclosure describes a patched extension release without describing revocation of tokens already issued [17][22].
What makes a stolen token worth that much is where Passportal put the crypto. The researchers report that the JWT access token itself carries the key material, under the fields "organization_key" and "phrase", and that decryption happens on N-able's servers, which return plaintext passwords and TOTP codes [13][12]. When they requested a password with decrypt=false, they could not open the result locally, which they read as evidence of a secret held server-side [14]. So the vendor's API is the decryption oracle and the token is the entry ticket [18]. That is the inverse of the end-to-end model the same write-up says every major password manager uses, where the server never sees the key [15].
It also sets the rotation scope. Because the server hands back TOTP codes as well as passwords [12], a token holder inside the window can mint working second factors [20]. Changing a password while leaving the vault-stored seed in place closes half the door. And the iframe was not handed credentials scoped to the current page: it got the tokens, which is why the researchers describe complete access to the decrypted vault [1]. Their earlier MultiPassword finding was narrower, limited to credentials sharing an eTLD with no whole-vault dump [16].
Scale is the part MSPs will feel. The extension had more than 73,000 affected weekly active users [3], on a product line N-able (formerly SolarWinds MSP) sells specifically to managed service providers [6]. Those seats belong to service providers rather than consumers, so the unit of loss is a provider's vault [23], and the finding carries a CVSS v4.0 base of 9.4 with CVE-2026-15580 reserved [2][5].
N-able's response was quick: the researchers asked for a test account on 6 July, had one on 8 July, and say a fix was published within 24 hours of their report [8][7]. That speed is also the reason anyone knows about this. The researchers say an automated pipeline flagged the pattern and they nearly dropped it because they could not verify anything without an account [21]. Vendors who do not hand out accounts get the quieter benefit of nobody checking.
Ranked by verification strength, evidence, and original report placement.
N-able's PassPortal extension on Chrome and Edge allowed any site or iframe a user is presented with to gain complete, persisted access to the decrypted vault for up to 100 days.
N-able, formerly SolarWinds MSP, is publicly traded at roughly $800M market cap and provides cloud-based remote monitoring, management and security platforms designed specifically for Managed Service Providers, including a password manager called PassPortal.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed single-source technical proof, no independent corroboration
The disclosure supplies unusually concrete artifacts: the offending listener code, the one-line postMessage that returns tokens, decoded JWT key material, and a four-step cURL proof-of-concept covering listing, decryption and live TOTP retrieval. A reserved CVE and named vulnerable/patched versions add specificity. But every claim traces to one publisher - the finders themselves - with no vendor advisory, no independent reproduction, and the story's headline operational point (tokens already taken survive the patch) resting on absence of stated revocation rather than confirmation.
Real install base and shipped fix, uptake unmeasured
There is concrete deployment evidence on both sides of the incident: a disclosed base of 73,000-plus affected weekly active users on Chrome and Edge, and a vendor patch shipped as v3.49.6 within 24 hours of report. What is absent is any measure of patch uptake, how many seats have moved off v3.49.5, or whether affected MSPs have rotated credentials - so adoption is anchored in the exposure population rather than in remediation progress.
Mostly proportionate, with unverified persistence framing
Severity language is largely earned: the code, the proof-of-concept and the CVSS 9.4 score support a serious finding, and the researchers deflate their own case in places by conceding the pattern is usually survivable and that they almost dropped the report. The overstatement is narrow but load-bearing - the framing that the patch stops the leak but not the tokens, and that access persists for up to 100 days, is asserted without vendor confirmation of token lifetime handling or any evidence of exploitation in the wild, alongside promotional framing of an autonomous discovery pipeline.
Researcher-owned disclosure promoting its own discovery pipeline
The only source is the finders' blog, which explicitly credits an autonomous vulnerability-discovery pipeline for flagging the issue and references the team's prior MultiPassword exploit. That creates a clear commercial and reputational interest in the finding reading as severe and novel. Partly offsetting: the post praises the vendor's PSIRT, discloses the limits of its earlier exploit, and admits it could not verify anything without a vendor-supplied account - disclosures that a purely promotional write-up would omit.
Technically credible but uncorroborated
Confidence is held mid-range: the technical core is specific, reproducible-looking and tied to a reserved CVE and named versions, which supports the factual claims. But there is one publisher with a stake in the outcome, no vendor advisory in the cluster, no exposure timeline, and the derived post-patch token-validity claim is unverified. That combination supports acting on the patch-and-rotate implication while withholding confidence on persistence and impact specifics.
build
Three ways to ask who embedded your iframe, and only one the host cannot switch off1 distinct publisher
invest
Mozilla's pitch against Gemini-wired Chrome is an off switch and a search deal with Exa2 distinct publishers
build
height:auto is animatable now, so your max-height ceiling is a bug you can delete1 distinct publisher
security
Kimsuky adds Chrome Remote Desktop to a toolkit it never retires1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026