CVE-2026-84941: TP-Link Systems Inc OC2000 v1
Medium severity, CVSS 6.9. EPSS: 0.5% chance of exploitation in the next 30 days.
An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.
Affected products
- TP-Link Systems Inc OC2000 v1: before 1.41.11 Build 20260711 (fixed in 1.41.11 Build 20260711)
- TP-Link Systems Inc OC2000 v2: before 2.26.11 Build 20260711 (fixed in 2.26.11 Build 20260711)
- TP-Link Systems Inc OC200 v3: before 3.3.11 Build 20260711 (fixed in 3.3.11 Build 20260711)
- TP-Link Systems Inc OC220 v1: before 1.6.11 Build 20260711 (fixed in 1.6.11 Build 20260711)
- TP-Link Systems Inc OC220 v2: before 2.5.11 Build 20260711 (fixed in 2.5.11 Build 20260711)
- TP-Link Systems Inc OC300 v1: before 1.35.11 Build 20260711 (fixed in 1.35.11 Build 20260711)
- TP-Link Systems Inc OC400 v1: before 1.13.11 Build 20260711 (fixed in 1.13.11 Build 20260711)
- TP-Link Systems Inc Omada Software Controller Linux: before 6.2.14.11 (fixed in 6.2.14.11)
- TP-Link Systems Inc Omada Software Controller Windows: before 6.2.14.11 (fixed in 6.2.14.11)
Published 2026-09-11. Last modified 2026-09-11.