CVE-2026-81531

An information disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users.  Successful exploitation may allow an attacker to remote query the affected endpoint that may facilitate user enumeration and subsequent attacks targeting administrative accounts.

  • Published Sep 8, 2026
  • CVSS 6.9 medium
  • 0.7% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-81531 at the National Vulnerability Database