Threat Intelligence

Password Vault Flaw Puts MSP and SMB Credentials at Risk

Dark Reading · 21 Aug 2026
Key Takeaway If your business uses a cloud-based password manager through an MSP, ask your provider about their master key protections and enable multi-factor authentication wherever possible.

A vulnerability has been discovered in Passportal, a password management tool widely used by managed service providers (MSPs) and small-to-medium businesses to store and protect sensitive login credentials. The flaw reportedly allowed exposure of master keys, the critical credentials that unlock access to an entire vault of stored passwords.

While N-able has issued a patch, security researchers note that the underlying risk may persist because Passportal, like many modern password managers, relies on a cloud-based architecture. This design means that even with fixes applied, the centralised, internet-connected nature of the service could continue to present an attractive target for attackers seeking to compromise multiple client accounts at once.

For small businesses that rely on MSPs to manage their IT security, this incident is a reminder that outsourcing password management doesn't eliminate risk entirely. Businesses should ask their service providers what security measures are in place beyond basic patching, including how master keys are protected and whether multi-factor authentication is enforced.

password security MSP risk vulnerability cloud security credential management

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.