The Vault Was Decrypted Server-Side, So the Token Is the Vault
One extension bug in an MSP-favoured credential manager produces an N-tenant disclosure event, and the vendor's fast patch does nothing about the tokens already in circulation.
The architecture sets the remediation cost. Passportal decrypts vaults server-side rather than end-to-end, so vault contents are recoverable by anyone holding a valid token. The extension flaw was disclosed by James Arnott and is tracked as CVE-2026-15580. It is a browser-extension messaging failure of the familiar class: main-world and iframe contexts are not meaningfully isolated. Any site the user visited could request tokens and receive them. So could any iframe inside it, including a third-party ad tag.
N-able's PSIRT remediated within roughly one to three days of disclosure. That is genuinely fast. It does not change the exposure arithmetic. A patch stops issuance. It does not revoke. Both access and refresh tokens went out, which is why the window runs up to 100 days instead of ending at the next session expiry, and why live TOTP retrieval is in scope alongside stored passwords.
The multiplication factor is the customer list, not the CVSS
Passportal is concentrated among managed service providers. The population of affected vaults is therefore not the population of affected browsers. One MSP technician's leaked token can enumerate credentials for every downstream tenant that provider administers. That includes organizations running the extension nowhere at all. This is the rare case where full exposure coexists with zero affected assets in local inventory.
| Remediation step | What it fixes | What it leaves open |
|---|---|---|
| Upgrade to extension 3.49.6 and enable admin version locking | New token leakage to sites and iframes | Every token issued before the upgrade |
| Revoke all access and refresh tokens | Replay of harvested session material | Secrets already read out of the vault |
| Rotate stored secrets and re-enroll TOTP seeds | Value of anything already enumerated | Nothing, if scope is complete |
| MSP written attestation | Your visibility into third-party exposure | Tenants whose provider does not answer |
Where the compliance trap sits
An extension inventory showing 3.49.6 everywhere is the artifact that will be presented as remediation evidence. It demonstrates nothing about whether harvested tokens were invalidated. Any control narrative for credential management resting on "patched within SLA" breaks here, because the SLA clock and the risk clock are measuring different things. The closure record should carry rotation completion, not a version number.
The procurement consequence
SANS NewsBites frames the root cause as vendor architecture rather than a coding defect. That is the durable lesson. A credential store that can decrypt on its own servers holds a skeleton key with a vendor's name on it, and every bearer token it issues is functionally a copy of that key. Client-side-only decryption belongs in the gating criteria for secrets and credential management tooling, next to SOC 2 scope and breach-notification SLAs.
Patching the password manager does not close this. The leaked vault tokens stay valid, which makes this a credential-rotation exercise wearing a patch cycle's clothing.
Two caveats worth logging. Exploitation in the wild has not been reported. The 100-day figure describes token validity, not confirmed dwell time. Neither changes the rotation decision, because a negative cannot be proven against tokens nobody can see.
What to do
Revoke every Passportal access and refresh token, rotate all stored secrets and re-enroll TOTP seeds within 72 hours, then confirm extension version 3.49.6 or later with admin version locking enabled
Request written remediation and rotation attestation from every MSP with Passportal in its stack by end of week, naming your tenants explicitly
Add client-side-only decryption as a gating requirement for credential and secrets management tooling at the next procurement review