CVE-2026-81531

Severity CVSS v4.0:
MEDIUM
Type:
CWE-200 Information Leak / Disclosure
Publication date:
08/09/2026
Last modified:
21/09/2026

Description

An information<br /> disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controller initialization<br /> remains accessible after completion and may disclose account-related<br /> information to unauthenticated remote users. <br /> <br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may allow an attacker to remote query the affected endpoint that<br /> may facilitate user enumeration and subsequent attacks targeting administrative<br /> accounts.