CVE-2026-84941
An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- CWE
- CWE-611
- Published
- 2026-09-10
- Last modified
- 2026-09-11
Affected products
- TP-Link Systems Inc. Omada Software Controller (Windows)
- TP-Link Systems Inc. Omada Software Controller (Linux)
- TP-Link Systems Inc. OC2000 v1
- TP-Link Systems Inc. OC2000 v2
- TP-Link Systems Inc. OC200 v3
- TP-Link Systems Inc. OC220 v1
- TP-Link Systems Inc. OC220 v2
- TP-Link Systems Inc. OC300 v1
Weakness type
Related vulnerabilities
- CVE-2026-19596 — OpenNMS XML collector XXE allows arbitrary file read from the OpenNMS host
- CVE-2026-19614 — XML External Entity (XXE) Injection in CyberELF NanoXML
- CVE-2026-71375 — XXE Vulnerability in Cosminexus Component Container
- CVE-2026-76958 — XML External Entity (XXE) Vulnerability in SAP Integration Suite
- CVE-2026-17443 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
- CVE-2026-17444 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
- CVE-2026-81832 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
- CVE-2026-82525 — Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing