CVE-2026-81531
An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users. Successful exploitation may allow an attacker to remote query the affected endpoint that may facilitate user enumeration and subsequent attacks targeting administrative accounts.
- Published Sep 8, 2026
- CVSS 6.9 medium
- 0.7% chance of exploitation in the next 30 days (EPSS)