{"id":"CVE-2026-84941","title":"An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of …","summary":"An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of …","severity":"medium","cvss":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-611"],"vendor":"TP-Link Systems Inc.","product":"Omada Software Controller (Windows)","affected":["omada_software_controller_windows < 6.2.14.11","omada_software_controller_linux < 6.2.14.11","oc2000_v1 < 1.41.11 Build 20260711","oc2000_v2 < 2.26.11 Build 20260711","oc200_v3 < 3.3.11 Build 20260711","oc220_v1 < 1.6.11 Build 20260711","oc220_v2 < 2.5.11 Build 20260711","oc300_v1 < 1.35.11 Build 20260711","oc400_v1 < 1.13.11 Build 20260711"],"published":"2026-09-11","updated":"2026-09-11","sourceUpdated":"2026-09-11T15:21:12.850","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84941","references":[{"url":"https://support.omadanetworks.com/en/document/133722/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://support.omadanetworks.com/en/download/software/omada-controller","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://support.omadanetworks.com/us/download/software/omada-controller","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.omadanetworks.com/en/support/download/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.omadanetworks.com/us/support/download/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-11T13:10:27.244979Z"},"cvssSource":"cna","ingestedAt":"2026-09-12T23:00:02.831Z","epss":0.00272,"epssPercentile":0.19838,"slug":"CVE-2026-84941","body":"## Overview\n\nAn information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":38,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}