MEDIUM 6.9 NVD
CVE-2026-84941
An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration
An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.
References
- https://support.omadanetworks.com/en/document/133722/
- https://support.omadanetworks.com/en/download/software/omada-controller
- https://support.omadanetworks.com/us/download/software/omada-controller
- https://www.omadanetworks.com/en/support/download/
- https://www.omadanetworks.com/us/support/download/
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-09-11 via NVD.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.