What is CVE-2026-84941?
CyStack AITP-Link Systems Inc. Omada Controller contains an information disclosure flaw in its SAML Single Sign-On (SSO) functionality because user-supplied SAML metadata is not sufficiently validated. An authenticated user with SAML configuration privileges can submit crafted XML to this processing path, which may lead to local file reads and disclosure of sensitive information. Operators should check every software controller and hardware controller using SAML SSO. The available evidence does not confirm real-world exploitation or the exact set of files that could be read.
