CVE-2026-84941

Summary

An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.Omada Software Controller (Windows)0 < 6.2.14.11affected
TP-Link Systems Inc.Omada Software Controller (Linux)0 < 6.2.14.11affected
TP-Link Systems Inc.OC2000 v10 < 1.41.11 Build 20260711affected
TP-Link Systems Inc.OC2000 v20 < 2.26.11 Build 20260711affected
TP-Link Systems Inc.OC200 v30 < 3.3.11 Build 20260711affected
TP-Link Systems Inc.OC220 v10 < 1.6.11 Build 20260711affected
TP-Link Systems Inc.OC220 v20 < 2.5.11 Build 20260711affected
TP-Link Systems Inc.OC300 v10 < 1.35.11 Build 20260711affected
TP-Link Systems Inc.OC400 v10 < 1.13.11 Build 20260711affected

Weaknesses

  • CWE-611: CWE-611 Improper restriction of XML external entity reference

References