SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81531

MEDIUM · CVSS 6.9 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An information disclosure vulnerability in Omada Controller allows unauthenticated remote users to access an API endpoint intended for initialization, potentially revealing account-related information. This could enable attackers to enumerate user accounts and launch targeted attacks against administrative accounts. Organizations using Omada Controller should prioritize addressing this vulnerability to mitigate the risk of unauthorized access and account compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81531
Severity
MEDIUM
CVSS
6.9
EPSS
0.38%

Original NVD Description

An information disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users.  Successful exploitation may allow an attacker to remote query the affected endpoint that may facilitate user enumeration and subsequent attacks targeting administrative accounts.