N-able’s Cloud-Based Password Manager Left Exposed by Critical Bug
A serious security vulnerability in N-able’s popular password manager, Passportal, has left thousands of businesses potentially vulnerable to complete compromise of their sensitive credentials. The bug, discovered by Bay Area Labs founder James Arnott on July 8, allowed any malicious website to obtain access to customers’ vaults, putting at risk the ultra-sensitive secrets managed by Passportal.
Passportal is a widely used credential management product that serves over 2,500 managed service providers (MSPs) and 165,000 small and medium-sized businesses (SMBs). The product operates on a cloud-based design, which has proven to be a double-edged sword. While it offers the convenience of remote access and scalability, its reliance on the cloud creates an attack surface that can be exploited by malicious actors.
The vulnerability in Passportal’s browser extension was particularly concerning, as it allowed any website to obtain complete, persistent access to customers’ vaults without requiring additional authentication or verification. This means that if a user visited a malicious website or one with injected malware, the password manager would unwittingly disclose its sensitive credentials. The access token obtained through this exploit could be used to enumerate and steal every single account credential in a Passportal vault.
Moreover, the stolen refresh token, which lasts for 100 days, allowed attackers to obtain a new access token as soon as an existing one expired. This created a persistent backdoor that could be exploited repeatedly. The implications of this bug are far-reaching, particularly considering that Passportal is commonly used by supply chain services providers. As Arnott noted, “If an attacker gains access to one MSP that manages 50 organizations, they would likely have highly privileged access to all of their downstream clients.”
The situation was further exacerbated by Passportal’s “Site” feature, which allows service providers to rebrand the password manager and redistribute it downstream to their own clients. This created a complex web of dependencies that could be exploited by attackers.
Fortunately, N-able acted swiftly in implementing a patch on July 9, just one day after the vulnerability was discovered. However, even with the updated product, users are still at risk due to the cloud-based design. As Arnott noted, “The master password generates access and refresh tokens, which carry the secret key. When an employee wants to log in, the access token travels to N-able’s servers, where it is used to unscramble the login information into plaintext.”
This approach creates a single point of failure that can be exploited by attackers. While mainstream password managers perform their most sensitive functions on a local machine to reduce this risk, Passportal’s reliance on cloud-based processing leaves its users vulnerable.
In light of this incident, it is essential for organizations using Passportal to take immediate action. They should review their password management practices and consider implementing additional security measures to mitigate the risks associated with cloud-based processing. This includes regularly updating software, enforcing strong password policies, and conducting regular security audits to identify potential vulnerabilities. By being proactive in addressing these issues, organizations can minimize the risk of a complete compromise of their sensitive credentials.
Source: Dark Reading — 2026-08-20