---
id: CVE-2026-81531
title: "An information\ndisclosure vulnerability has been identified in Omada Controller.\_ An API endpoint intended for Controller initialization\nremains accessible after completion and may disclose account-related\ninformation to unauthenticated …"
summary: "An information\ndisclosure vulnerability has been identified in Omada Controller.\_ An API endpoint intended for Controller initialization\nremains accessible after completion and may disclose account-related\ninformation to unauthenticated …"
severity: medium
cvss: 6.9
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-200
vendor: TP-Link System Inc.
product: Omada Software Controller
affected:
  - omada_software_controller < 6.3.0.45
  - oc200_v1 < (UN)_V1_1.42.10 Build 20260825
  - oc200_v2 < (UN)_V2_2.27.10 Build 20260825
  - oc200_v3 < (UN)_V3_3.4.10 Build 20260825
  - oc220_v1 < (UN)_V1_1.7.10 Build 20260825
  - oc220_v2 < (UN)_V2_2.6.10 Build 20260825
  - oc300_v1 < (UN)_V1_1.36.10 Build 20260825
  - oc400_v1 < (UN)_V1_1.14.10 Build 20260825
published: '2026-09-08'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T18:17:10.900'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81531'
references:
  - url: 'https://support.omadanetworks.com/en/download/software/omada-controller/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://support.omadanetworks.com/us/document/133567/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://support.omadanetworks.com/us/download/software/omada-controller/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-08T17:21:39.911958Z'
cvssSource: cna
epss: 0.00666
epssPercentile: 0.49706
ingestedAt: '2026-09-08T19:08:49.600Z'
---

## Overview

An information
disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controller initialization
remains accessible after completion and may disclose account-related
information to unauthenticated remote users. 






Successful
exploitation may allow an attacker to remote query the affected endpoint that
may facilitate user enumeration and subsequent attacks targeting administrative
accounts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
