A public proof of concept for CVE-2026-60104 puts the spotlight on a familiar but dangerous failure mode: backend trust, not encryption, can become the weak link in a password manager.