Information Disclosure Vulnerability in Omada Controller by Omada Networks
CVE-2026-84941
6.9MEDIUM
Key Information:
- Vendor
Tp-link Systems Inc.
- Vendor
- CVE Published:
- 10 September 2026
What is CVE-2026-84941?
An information disclosure vulnerability in the SAML Single Sign-On (SSO) feature of Omada Controller enables authenticated users with SAML configuration permissions to access sensitive data. This is primarily due to inadequate validation of user-provided SAML metadata. When exploited, the vulnerability could lead to the unauthorized exposure of critical information, posing risks to user privacy and system integrity.
Affected Version(s)
OC200 v3 Omada Controller 0 < 3.3.11 Build 20260711
OC2000 v1 Omada Controller 0 < 1.41.11 Build 20260711
OC2000 v2 Omada Controller 0 < 2.26.11 Build 20260711
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
erikdejong
mattgsys
eslam moneer (tohtmosiii)
