CVE-2026-84941 PUBLISHED

Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading to Arbitrary Local File Read

Assigner: TPLink
Reserved: 02.09.2026 Published: 10.09.2026 Updated: 10.09.2026

An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor TP-Link Systems Inc.
Product Omada Software Controller (Windows)
Versions Default: unaffected
  • affected from 0 to 6.2.14.11 (excl.)
Vendor TP-Link Systems Inc.
Product Omada Software Controller (Linux)
Versions Default: unaffected
  • affected from 0 to 6.2.14.11 (excl.)
Vendor TP-Link Systems Inc.
Product OC2000 v1
Versions Default: unaffected
  • affected from 0 to 1.41.11 Build 20260711 (excl.)
Vendor TP-Link Systems Inc.
Product OC2000 v2
Versions Default: unaffected
  • affected from 0 to 2.26.11 Build 20260711 (excl.)
Vendor TP-Link Systems Inc.
Product OC200 v3
Versions Default: unaffected
  • affected from 0 to 3.3.11 Build 20260711 (excl.)
Vendor TP-Link Systems Inc.
Product OC220 v1
Versions Default: unaffected
  • affected from 0 to 1.6.11 Build 20260711 (excl.)
Vendor TP-Link Systems Inc.
Product OC220 v2
Versions Default: unaffected
  • affected from 0 to 2.5.11 Build 20260711 (excl.)
Vendor TP-Link Systems Inc.
Product OC300 v1
Versions Default: unaffected
  • affected from 0 to 1.35.11 Build 20260711 (excl.)
Vendor TP-Link Systems Inc.
Product OC400 v1
Versions Default: unaffected
  • affected from 0 to 1.13.11 Build 20260711 (excl.)

Credits

  • erikdejong finder
  • mattgsys finder
  • eslam moneer (tohtmosiii) finder

References

Problem Types

  • CWE-611 Improper restriction of XML external entity reference CWE

Impacts

  • CAPEC-221 Data Serialization External Entities Blowup