A Critical Vulnerability in N-able’s Passportal Exposes Password Vault Master Keys
A disturbing security flaw has been discovered in Passportal, a popular password manager used by thousands of managed service providers (MSPs) and small to medium-sized businesses (SMBs). The vulnerability allows any malicious website to gain complete, persistent access to customers’ vaults, putting sensitive credentials at risk. Despite a patch being released by the vendor, N-able, experts warn that even the updated product carries some level of risk for users.
The issue lies in Passportal’s cloud-based design, which differs from most mainstream password managers that perform their most sensitive functions on a local machine to reduce the risk of Web-based attacks. In contrast, Passportal generates access and refresh tokens that carry the secret key, which is then sent to N-able’s servers for decryption. This process makes it possible for hackers to intercept and steal access tokens, allowing them to enumerate and steal every single account credential in a vault.
The browser extension used by Passportal was found to be entirely undiscerning, trusting every message it received without verifying the sender or contents. This made it relatively easy for hackers to lure users into visiting malicious websites or injecting malware into legitimate ones, which would then allow them to obtain access tokens and subsequently gain control over the password vault.
The stolen refresh token is particularly worrying, as it allows attackers to obtain a new access token every 100 days, effectively granting them persistent access to the password manager. This vulnerability is even more concerning when considering that Passportal is often used by supply chain service providers, which can have far-reaching consequences if compromised.
For example, an attacker could gain access to one MSP and then use their highly privileged access to manage all of their downstream clients. The risk expands further with the “branded password management as a service” feature, known as “Site,” which allows service providers to rebrand Passportal and redistribute it to their own clients.
The discovery of this vulnerability highlights the importance of careful design choices in cloud-based security solutions. While N-able has released a patch to address the issue, experts warn that even updated products carry some level of risk for users. To mitigate this risk, organizations using Passportal should consider implementing additional security measures, such as two-factor authentication and regular password rotations.
Ultimately, this vulnerability serves as a reminder that no security solution is foolproof, and even seemingly robust systems can be vulnerable to clever exploitation. By staying vigilant and taking proactive steps to protect their sensitive credentials, individuals and organizations can minimize the risk of falling victim to such attacks.
Source: Dark Reading — 2026-08-20