PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84941 TP-Link Systems Inc. CVE debrief

CVE-2026-84941 is an information disclosure vulnerability in Omada Controller's SAML Single Sign-On (SSO) functionality. An authenticated user with SAML configuration privileges can access sensitive information due to insufficient validation of user-supplied SAML metadata. This CVE was published on 2026-09-11T00:19:57.633Z and last modified on 2026-09-11T15:21:12.850Z.

Vendor
TP-Link Systems Inc.
Product
Omada Software Controller (Windows)
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-11
Original CVE updated
2026-09-11
Advisory published
2026-09-11
Advisory updated
2026-09-11

Who should care

Defenders responsible for configuring and maintaining Omada Controller should assess exposure and prioritize verification and updates to prevent unauthorized access. This includes reviewing SAML configuration privileges, verifying affected versions, and applying patches or mitigations as needed. Security teams and vulnerability management teams should also be aware of this vulnerability and its potential impact on their systems.

Why it matters

CVE-2026-84941 is a medium-severity information disclosure vulnerability in Omada Controller's SAML SSO functionality. Defenders should prioritize verifying and updating configurations to prevent unauthorized access.

  • Potential unauthorized disclosure of sensitive information
  • Need to verify and update Omada Controller configurations
  • Possible impact on SSO functionality

Technical summary

The CVE-2026-84941 vulnerability is caused by insufficient validation of user-supplied SAML metadata in Omada Controller's SAML SSO functionality. An authenticated user with SAML configuration privileges can exploit this vulnerability to access sensitive information. This could lead to unauthorized disclosure of sensitive information. The vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. Defenders should prioritize verifying and updating Omada Controller configurations to prevent unauthorized access, focusing on SAML configuration privileges and metadata validation.

Defensive priority

Defenders should prioritize verifying and updating Omada Controller configurations to prevent unauthorized access.

Recommended defensive actions

  • Verify and update Omada Controller configurations to prevent unauthorized access
  • Restrict access to SAML configuration privileges
  • Monitor for suspicious activity related to SAML metadata
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information about affected versions, remediation steps, and verification tasks is needed. Defenders should verify the affected Omada Controller versions, review SAML configuration privileges, and check for any available patches or updates. Evidence limits suggest focusing on CVE and NVD details for now.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84941 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84941

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84941 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84941

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://support.omadanetworks.com/en/document/133722/

    f23511db-6c3e-4e32-a477-6aa17d310630

  • Source reference

    Unverified legacy reference

    URL: https://support.omadanetworks.com/en/download/software/omada-controller

    f23511db-6c3e-4e32-a477-6aa17d310630

  • Source reference

    Unverified legacy reference

    URL: https://support.omadanetworks.com/us/download/software/omada-controller

    f23511db-6c3e-4e32-a477-6aa17d310630

  • Source reference

    Unverified legacy reference

    URL: https://www.omadanetworks.com/en/support/download/

    f23511db-6c3e-4e32-a477-6aa17d310630

  • Source reference

    Unverified legacy reference

    URL: https://www.omadanetworks.com/us/support/download/

    f23511db-6c3e-4e32-a477-6aa17d310630

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.