N-able Bug Exposes Password Vault Master Keys
N-able Passportal, a popular password manager used by MSPs and SMBs, has a significant security vulnerability allowing malicious websites to steal users' vault credentials. The browser extension blindly trusts all incoming messages, enabling attackers to extract access and refresh tokens, leading to complete password vault compromise. Despite a patch, the product’s cloud-based design and server-side decryption continue to present substantial risks, particularly due to its use within the supply chain. Proactive administrators should consider version locking to prevent automatic updates and ensure users are on a secure version.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
