Executive brief
Gallagher's Command Centre Mobile Client, used by security operators to manage access control systems, stores session tokens in cleartext on Android and iOS devices. An attacker with physical access to a logged-in operator's phone can extract the session token and impersonate that user for a limited time, potentially gaining unauthorized access to door locks, security systems, and facility management functions.
Technical details
The vulnerability is a cleartext storage flaw (CWE-312) affecting the Command Centre Mobile Client for Android and iOS. Session tokens, which authenticate an operator to the access control system, are stored unencrypted on the device where they can be accessed by an attacker with local device access. The attack requires the device to already be compromised or unlocked (high privilege assumption), but does not require user interaction once access is gained. An attacker can extract the token and use it to make API calls or perform actions within the Command Centre until the session expires. The fix is available in version 9.40.123 and later.
Affected products
- Gallagher Command Centre Mobile Client Prior to 9.40.123
Timeline
- 2026-03-03: disclosed: Published by Gallagher and NVD