A permissive web security configuration may allow cross...
Low severity
Unreviewed
Published
Feb 13, 2026
to the GitHub Advisory Database
•
Updated Feb 14, 2026
Description
Published by the National Vulnerability Database
Feb 13, 2026
Published to the GitHub Advisory Database
Feb 13, 2026
Last updated
Feb 14, 2026
A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow unauthorized disclosure of sensitive information. Fixed in updated Omada Cloud Controller service versions deployed automatically by TP‑Link. No user action is required.
References