Junglewise Threat Intelligence

CVE-2026-84941: TP-Link Omada Controller XXE injection in SAML metadata parsing

CVE-2026-84941 · Severity: info · CVSS 6.9 · Published 2026-09-11

Vendors: TP-Link.

Executive brief

Omada Controller is a centralized management platform for TP-Link networking equipment. An authenticated administrator with SAML SSO configuration privileges can exploit an XML External Entity (XXE) injection vulnerability to read arbitrary files from the controller's local filesystem, potentially exposing configuration files, credentials, and other sensitive system data.

Technical details

The vulnerability is an XXE injection in the SAML IdP metadata parsing logic within Omada Controller's SSO functionality. An authenticated user with SAML configuration privileges can supply malicious SAML metadata containing external entity declarations to extract local files. The attack requires network access to the controller and valid administrative credentials with SAML configuration rights. Successful exploitation results in unauthorized disclosure of sensitive information stored on the controller. Patches are available: Omada Software Controller 6.2.14.11, OC200 v1/v2/v3 1.41.11/2.26.11/3.3.11, OC220 v1/v2 1.6.11/2.5.11, OC300 1.35.11, and OC400 1.13.11.

Affected products

  • TP-Link Omada Software Controller before 6.2.14.11
  • TP-Link OC200 v1 before 1.41.11, v2 before 2.26.11, v3 before 3.3.11
  • TP-Link OC220 v1 before 1.6.11, v2 before 2.5.11
  • TP-Link OC300 v1 before 1.35.11
  • TP-Link OC400 v1 before 1.13.11

Timeline

  • 2026-09-10: disclosed: Security advisory published
  • 2026-07-11: patched: Patch released for hardware-based appliances (OC200/OC220/OC300/OC400) build 20260711
  • 2026-07-17: patched: Patch released for Omada Software Controller version 6.2.14.11

References