A Flaw in N-able's Passportal Handed Any Malicious Website the Keys to Every Password a Business Stored
A researcher found that Passportal's browser extension trusted every message it received without question, letting any webpage silently drain a company's entire vault of login credentials.

Key points
- On 8 July, researcher James Arnott discovered that any malicious website could silently steal all credentials stored in N-able's Passportal password manager.
- Passportal is used by roughly 2,500 managed service providers (MSPs) and 165,000 small and medium-sized businesses, making the potential blast radius unusually large.
- A stolen refresh token, valid for 100 days, would let attackers keep returning to a victim's vault even after login sessions expired.
- N-able shipped a patch on 9 July, but Arnott says the product's core design still leaves customer passwords exposed on the company's own servers.
- N-able said it is "continuously evaluating further hardening measures" but has not committed to a specific architectural fix.
Password managers are supposed to be the safest place a business can keep its login credentials. For tens of thousands of companies using N-able's Passportal, that assumption turned out to be wrong.
Passportal is a cloud-based password manager sold by N-able, formerly the managed-service arm of SolarWinds and now a publicly traded company approaching a billion dollars in annual revenue. It's aimed at managed service providers (MSPs), meaning IT firms that handle the computer systems of dozens or hundreds of smaller client businesses on their behalf.
How did the flaw work?
The problem was in Passportal's browser extension, a small add-on that helps employees log in to websites automatically. It accepted instructions from any webpage without checking whether that page was allowed to send them.
Most password managers do their sensitive work locally, on the user's own device. The master password (the single credential that unlocks all the others) generates a secret key on that device, and the key never leaves it. Passportal works differently: when an employee retrieves a stored password, the request travels to N-able's servers, which decrypt the password and send it back.
To authorise those server calls, Passportal issued users an "access token", a digital pass proving the request is legitimate. Bay Area Labs found that any site a user visited could send the extension a simple command and receive that token in reply, no sophisticated attack required. A malicious advertisement on an otherwise legitimate page would've been enough.
With the token in hand, an attacker could pull every stored username and password from the vault. They could also grab stored codes used for two-factor authentication (the six-digit numbers that change every 30 seconds, used as a second lock on accounts). Because Passportal also handed over a "refresh token", a secondary credential that generates fresh access tokens, an attacker could return to the vault as often as needed for up to 100 days.
Why does it matter that MSPs were the target?
One compromised MSP is rarely just one victim. A single IT firm might manage networks for 50 businesses. Passportal's "Site" feature lets MSPs rebrand and resell the product to their own clients, so a breach could cascade two layers deep before it stops.
| Detail | Figure |
|---|---|
| Passportal MSP customers | ~2,500 |
| Small and medium businesses using Passportal | ~165,000 |
| Refresh token validity window | 100 days |
| Patch deployed | 9 July 2025 |
| Flaw discovered | 8 July 2025 |
Arnott is the same researcher we covered on 10 August for finding that Belgium's most-used digital identity tool could let any malicious website steal a user's PIN or forge their electronic signature. That his Passportal findings also centre on a browser extension accepting untrusted messages isn't a coincidence: it's a pattern worth watching.
N-able issued a fix the day after Arnott reported the problem, first covered by Dark Reading. The patch checks that instructions to the extension come from the extension itself, not from a random website. Browser extensions normally update silently, but Arnott suggests IT administrators lock their organisation's extensions to a specific version through the Google Workspace admin console, then approve updates manually, so every machine in the organisation stays in sync.
Is the problem fully fixed?
Not entirely. The patch stops outside websites from grabbing tokens, but Passportal still decrypts passwords on N-able's servers rather than on the user's device. Unscrambled passwords exist, briefly, on infrastructure the customer doesn't control. If N-able's servers were breached, or if traffic were intercepted in transit, those passwords could still be exposed.
Arnott told Dark Reading his verdict plainly: "If I found out my password manager didn't have end-to-end encryption, there's no way I would use it." N-able's response, also given to Dark Reading, was that the company is "continuously evaluating further hardening measures." That's not a commitment to end-to-end encryption (where only the user's device ever sees the unscrambled password), and businesses should read it that way.
Confirm your browser extensions have updated, audit which accounts sit in the vault, and reset passwords for the most sensitive systems as a precaution. If you're a customer of an MSP and don't know whether they use Passportal, ask.



