Information Disclosure Vulnerability in Omada Controller by Omada Networks
CVE-2026-84941

6.9MEDIUM

What is CVE-2026-84941?

An information disclosure vulnerability in the SAML Single Sign-On (SSO) feature of Omada Controller enables authenticated users with SAML configuration permissions to access sensitive data. This is primarily due to inadequate validation of user-provided SAML metadata. When exploited, the vulnerability could lead to the unauthorized exposure of critical information, posing risks to user privacy and system integrity.

Affected Version(s)

OC200 v3 Omada Controller 0 < 3.3.11 Build 20260711

OC2000 v1 Omada Controller 0 < 1.41.11 Build 20260711

OC2000 v2 Omada Controller 0 < 2.26.11 Build 20260711

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

erikdejong
mattgsys
eslam moneer (tohtmosiii)
.