CVE-2026-84941
Received Received - Intake

SAML SSO Information Disclosure in Omada Controller

Vulnerability report for CVE-2026-84941, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: TPLink

Description

An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
tp-link omada_software_controller 6.1.0.19
tp-link oc200 *
tp-link oc220 *
tp-link oc300 *
tp-link oc400 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-611 The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller. It occurs because the system does not properly validate user-supplied SAML metadata, allowing an authenticated user with SAML configuration privileges to exploit an XML External Entity (XXE) injection. This can lead to unauthorized access to sensitive information, including arbitrary local file reads.

Detection Guidance

To detect this vulnerability, monitor for unusual SAML metadata processing or XML External Entity (XXE) injection attempts in Omada Controller logs. Check for unauthorized file access patterns or unexpected data exposure in network traffic involving the controller. Review logs for users with SAML configuration privileges performing unexpected actions.

Impact Analysis

An attacker with SAML configuration privileges could exploit this to read sensitive files on the system, potentially exposing confidential data such as credentials, configuration files, or other sensitive information stored locally. This could lead to further compromise of the network or systems managed by the Omada Controller.

Compliance Impact

This vulnerability could lead to unauthorized disclosure of personal or sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations using affected Omada Controller versions may face legal and regulatory penalties if sensitive data is exposed due to this flaw.

Mitigation Strategies

Immediately update Omada Controller to the latest firmware version provided by TP-Link. Restrict SAML configuration privileges to only necessary users. Disable unnecessary XML parsing features if possible. Monitor for suspicious activity and apply network segmentation to limit exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84941. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart