CVE-2026-84941
6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | Omada Software Controller (Windows) | 0 < 6.2.14.11 | affected |
| TP-Link Systems Inc. | Omada Software Controller (Linux) | 0 < 6.2.14.11 | affected |
| TP-Link Systems Inc. | OC2000 v1 | 0 < 1.41.11 Build 20260711 | affected |
| TP-Link Systems Inc. | OC2000 v2 | 0 < 2.26.11 Build 20260711 | affected |
| TP-Link Systems Inc. | OC200 v3 | 0 < 3.3.11 Build 20260711 | affected |
| TP-Link Systems Inc. | OC220 v1 | 0 < 1.6.11 Build 20260711 | affected |
| TP-Link Systems Inc. | OC220 v2 | 0 < 2.5.11 Build 20260711 | affected |
| TP-Link Systems Inc. | OC300 v1 | 0 < 1.35.11 Build 20260711 | affected |
| TP-Link Systems Inc. | OC400 v1 | 0 < 1.13.11 Build 20260711 | affected |
Weaknesses
- CWE-611: CWE-611 Improper restriction of XML external entity reference
References
- https://support.omadanetworks.com/en/download/software/omada-controller
- https://support.omadanetworks.com/us/download/software/omada-controller
- https://www.omadanetworks.com/en/support/download/
- https://www.omadanetworks.com/us/support/download/
- https://support.omadanetworks.com/en/document/133722/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.