CVE-2026-84941: Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading to Arbitrary Local File Read
An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires an authenticated Omada Controller user who has privileges to configure SAML. It is not described as exploitable by unauthenticated users or by users without SAML configuration access.
What must an attacker provide to trigger the vulnerability?
The attacker must supply SAML identity provider metadata to the Controller's SAML SSO configuration. Insufficient validation of that user-supplied metadata enables XML external entity processing and may disclose sensitive local information.
What is the potential impact?
Successful exploitation can disclose sensitive information, including through arbitrary local file reads. The provided information does not state that the issue enables modification of files, remote code execution, or privilege escalation.