XXE in SAML metadata parsing exposes local information in TP-Link Omada Controller

What is CVE-2026-84941?

CyStack AI

TP-Link Systems Inc. Omada Controller contains an information disclosure flaw in its SAML Single Sign-On (SSO) functionality because user-supplied SAML metadata is not sufficiently validated. An authenticated user with SAML configuration privileges can submit crafted XML to this processing path, which may lead to local file reads and disclosure of sensitive information. Operators should check every software controller and hardware controller using SAML SSO. The available evidence does not confirm real-world exploitation or the exact set of files that could be read.

Overview

Original source data

An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.

Affected products and scope

The normalized record marks versions below the following boundaries as affected and sets the default status to unaffected for values not otherwise listed. The vendor advisory names the two hardware entries OC200, while the normalized record labels them OC2000 v1 and OC2000 v2; verify the model name in inventory before updating.

  • Omada Software Controller (Windows): affected below 6.2.14.11; fixed in 6.2.14.11.
  • Omada Software Controller (Linux): affected below 6.2.14.11; fixed in 6.2.14.11.
  • OC200 v1, corresponding to the normalized OC2000 v1 entry: affected below 1.41.11 Build 20260711; fixed firmware is 1.41.11 Build 20260711.
  • OC200 v2, corresponding to the normalized OC2000 v2 entry: affected below 2.26.11 Build 20260711; fixed firmware is 2.26.11 Build 20260711.
  • OC200 v3: affected below 3.3.11 Build 20260711; fixed firmware is 3.3.11 Build 20260711.
  • OC220 v1: affected below 1.6.11 Build 20260711; fixed firmware is 1.6.11 Build 20260711.
  • OC220 v2: affected below 2.5.11 Build 20260711; fixed firmware is 2.5.11 Build 20260711.
  • OC300 v1: affected below 1.35.11 Build 20260711; fixed firmware is 1.35.11 Build 20260711.
  • OC400 v1: affected below 1.13.11 Build 20260711; fixed firmware is 1.13.11 Build 20260711.

Parallel branches or versions not listed separately should not be assumed to be unaffected merely because one branch has a fix.

Technical details

The flaw is in the SAML Single Sign-On (SSO) metadata parser, specifically the processing of SAML Identity Provider (IdP) metadata. An attacker needs an authenticated account with SAML configuration privileges and must be able to submit attacker-controlled SAML metadata to this functionality. The vendor advisory identifies insufficient validation that permits XML External Entity (XXE) injection, classified as CWE-611, and can lead to local file reads depending on the controller process's access. The supplied vector indicates network reachability, low attack complexity, no user interaction, and a high privilege requirement. The available evidence does not identify a specific endpoint, XML library, payload, readable file set, or exact limit on the disclosed data.

Exploitability

The flaw is reachable through the Omada Controller network interface. Exploitation requires an authenticated account with SAML configuration privileges; no additional user interaction is required, and the supplied record rates attack complexity as low. The vendor advisory describes the issue as XXE injection during SAML IdP metadata parsing, with a resulting ability to read local files and disclose information. The supplied record does not confirm real-world exploitation or a public exploit, so the actual exploitation status is not established.

Technical impact

Successful exploitation can allow an authenticated user with SAML configuration privileges to make the metadata parser process external XML entities and read local data accessible to the controller process. The confirmed advisory-level outcome is unauthorized information disclosure, with the technical advisory title describing the possibility of arbitrary local file read. The primary impact is confidentiality loss; the record does not indicate data modification or service disruption. There is no evidence that the flaw itself provides privilege escalation, and the exact files or information that can be read have not been disclosed.

Business impact

The primary business impact is loss of confidentiality on systems running Omada Controller.

  • If XXE processing can read files accessible to the controller process, local configuration data or other sensitive information could be disclosed.
  • The attacker must already hold an authenticated account with SAML configuration privileges, so exposure depends substantially on administrative account protection and access control.
  • Disclosed data could increase the consequences of an account compromise or support further investigation, but the available evidence does not establish access to a specific organization or data type.
  • The advisory does not describe a direct impact on data integrity or service availability.

Remediation

  1. Update the affected branch. TP-Link Systems Inc. recommends updating affected devices to the fixed release. For Omada Software Controller on Windows and Linux, use 6.2.14.11. For OC200 v1, use 1.41.11 Build 20260711; OC200 v2, 2.26.11 Build 20260711; OC200 v3, 3.3.11 Build 20260711; OC220 v1, 1.6.11 Build 20260711; OC220 v2, 2.5.11 Build 20260711; OC300 v1, 1.35.11 Build 20260711; and OC400 v1, 1.13.11 Build 20260711.
  2. Verify the actual model and hardware version before updating. In particular, the advisory uses OC200 v1 and OC200 v2, while the normalized record uses OC2000 v1 and OC2000 v2.
  3. Re-test SAML SSO after the update, including IdP metadata import and the permissions of accounts that can modify SAML configuration.
  4. Until updating is possible, restrict SAML configuration privileges under least privilege, review and disable unnecessary accounts, and limit administrative network access to the controller. This is precautionary risk reduction; the advisory does not provide a specific technical workaround.
  5. Do not treat a fix for one branch as evidence that other branches or models are fixed. For versions outside the confirmed boundaries, verify status directly against the vendor's release information.

Detection

  1. Inventory all Omada Software Controllers and hardware controllers that use SAML SSO, recording each platform and product branch.
  2. Check installed versions and compare them with the vendor-fixed release for the relevant branch in affected_summary or remediation. Do not treat a fix for one branch as evidence that every other branch is safe.
  3. Review accounts with SAML configuration privileges, especially unnecessary accounts or accounts showing unexpected use.
  4. Review audit and application logs for SAML metadata changes, XML parsing errors, or unusual file access around relevant administrative activity. This is precautionary monitoring because the available evidence does not provide a named log event, IOC, or specific log pattern.
  5. Confirm that updates came from TP-Link Systems Inc.'s official distribution channels and were applied to the correct model, hardware version, and operating system.
Sources (5)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan
CyStack VulnScan dashboard