news.mlab.sh
Back to the feed
vulnerability

N-able Bug Exposes Password Vault Master Keys

High
Image: Dark Reading
Summary

N-able Passportal, a popular password manager used by MSPs and SMBs, has a significant security vulnerability allowing malicious websites to steal users' vault credentials. The browser extension blindly trusts all incoming messages, enabling attackers to extract access and refresh tokens, leading to complete password vault compromise. Despite a patch, the product’s cloud-based design and server-side decryption continue to present substantial risks, particularly due to its use within the supply chain. Proactive administrators should consider version locking to prevent automatic updates and ensure users are on a secure version.

Read the full article at Dark Reading

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.