CVE-2026-84941 Details
Description
An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.
A vulnerability allowing information disclosure exists in the SAML Single Sign-On (SSO) feature of the Omada Controller. This issue arises from inadequate validation of user-provided SAML metadata, which allows an authenticated user with SAML configuration privileges to access sensitive information. Successful exploitation of this vulnerability could lead to unauthorized disclosure of confidential data.
Users are advised to update to version 6.2.14.11 for the Omada Software Controller on Windows or Linux. For OC200, OC220, OC300, and OC400 devices, version 1.41.11 Build 20260711, 1.6.11 Build 20260711, 1.35.11 Build 20260711, and 1.13.11 Build 20260711 respectively should be installed. Instructions for downloading the updated Omada Software Controller can be found on the TP-Link Omada Download Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 11, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.omadanetworks.com/en/document/133722/ | TPLink | AdvisoryRemedyVendor |
| https://support.omadanetworks.com/en/download/software/omada-controller | TPLink | ProductVendor |
| https://support.omadanetworks.com/us/download/software/omada-controller | TPLink | ProductVendor |
| https://www.omadanetworks.com/en/support/download/ | TPLink | Permission RequiredVendor |
| https://www.omadanetworks.com/us/support/download/ | TPLink | Permission RequiredVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | TPLink |
Affected Products
| Product | Versions |
|---|---|
| TP-Link Omada Controller | >= 6.2.0.17, < 6.2.14.11 >= 6.2.10.17, < 6.2.14.11 >= 6.2.14.11, < 6.2.14.11 >= 5.15.24.18, < 5.15.24.19 >= 5.15.24.17, < 5.15.24.19 >= 5.15.20.20, < 5.15.20.21 |
CPE
Remediation
| |
| TP-Link OC200 | All versions |
CPE
Remediation
| |
| TP-Link OC220 | All versions |
CPE
Remediation
| |
| TP-Link OC300 | All versions |
CPE
Remediation
| |
| TP-Link OC400 | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | CISA-ADP |
| Sep 11, 2026 | New CVE Received | TPLink |
Volerion