PatchSiren cyber security CVE debrief
CVE-2026-84941 TP-Link Systems Inc. CVE debrief
CVE-2026-84941 is an information disclosure vulnerability in Omada Controller's SAML Single Sign-On (SSO) functionality. An authenticated user with SAML configuration privileges can access sensitive information due to insufficient validation of user-supplied SAML metadata. This CVE was published on 2026-09-11T00:19:57.633Z and last modified on 2026-09-11T15:21:12.850Z.
- Vendor
- TP-Link Systems Inc.
- Product
- Omada Software Controller (Windows)
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-11
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-09-11
- Advisory updated
- 2026-09-11
Who should care
Defenders responsible for configuring and maintaining Omada Controller should assess exposure and prioritize verification and updates to prevent unauthorized access. This includes reviewing SAML configuration privileges, verifying affected versions, and applying patches or mitigations as needed. Security teams and vulnerability management teams should also be aware of this vulnerability and its potential impact on their systems.
Why it matters
CVE-2026-84941 is a medium-severity information disclosure vulnerability in Omada Controller's SAML SSO functionality. Defenders should prioritize verifying and updating configurations to prevent unauthorized access.
- Potential unauthorized disclosure of sensitive information
- Need to verify and update Omada Controller configurations
- Possible impact on SSO functionality
Technical summary
The CVE-2026-84941 vulnerability is caused by insufficient validation of user-supplied SAML metadata in Omada Controller's SAML SSO functionality. An authenticated user with SAML configuration privileges can exploit this vulnerability to access sensitive information. This could lead to unauthorized disclosure of sensitive information. The vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. Defenders should prioritize verifying and updating Omada Controller configurations to prevent unauthorized access, focusing on SAML configuration privileges and metadata validation.
Defensive priority
Defenders should prioritize verifying and updating Omada Controller configurations to prevent unauthorized access.
Recommended defensive actions
- Verify and update Omada Controller configurations to prevent unauthorized access
- Restrict access to SAML configuration privileges
- Monitor for suspicious activity related to SAML metadata
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information about affected versions, remediation steps, and verification tasks is needed. Defenders should verify the affected Omada Controller versions, review SAML configuration privileges, and check for any available patches or updates. Evidence limits suggest focusing on CVE and NVD details for now.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-84941 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-84941
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-84941 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84941
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://support.omadanetworks.com/en/document/133722/
f23511db-6c3e-4e32-a477-6aa17d310630
-
Source reference
Unverified legacy reference
URL: https://support.omadanetworks.com/en/download/software/omada-controller
f23511db-6c3e-4e32-a477-6aa17d310630
-
Source reference
Unverified legacy reference
URL: https://support.omadanetworks.com/us/download/software/omada-controller
f23511db-6c3e-4e32-a477-6aa17d310630
-
Source reference
Unverified legacy reference
URL: https://www.omadanetworks.com/en/support/download/
f23511db-6c3e-4e32-a477-6aa17d310630
-
Source reference
Unverified legacy reference
URL: https://www.omadanetworks.com/us/support/download/
f23511db-6c3e-4e32-a477-6aa17d310630
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.