CVE-2026-81531: Unauthenticated Account Information Disclosure in Multiple Omada Controllers
An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users.
Successful exploitation may allow an attacker to remote query the affected endpoint that may facilitate user enumeration and subsequent attacks targeting administrative accounts.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Unauthenticated remote users can query the exposed API endpoint. No account or prior authentication is described as necessary.
What information could be exposed and how could it be used?
The endpoint may disclose account-related information, which can facilitate user enumeration. Enumerated users may then be targeted in subsequent attacks against administrative accounts.
When is the affected endpoint exposed?
The endpoint is intended only for Controller initialization but remains accessible after initialization has completed.
How can I determine whether a controller is affected?
Check whether the Controller's initialization API endpoint remains remotely accessible after initialization and whether an unauthenticated request returns account-related information.