Executive brief
Gallagher Command Centre Server is a critical component of enterprise access control and security management systems. A locking vulnerability in the Morpho biometric integration allows a privileged operator to cause temporary unavailability of the system, potentially disrupting access control operations at a facility.
Technical details
An improper locking vulnerability (CWE-667) exists in the Gallagher Morpho biometric integration component within Command Centre Server. The vulnerability allows a user with privileged operator credentials to trigger a limited denial-of-service condition. The attack requires local access, high attack complexity, and valid operator privileges. The impact is limited to temporary availability disruption with no impact on confidentiality or integrity. Patches are available across all affected versions: 9.40.1976 MR1, 9.30.3382 MR4, 9.20.3783 MR6, 9.10.4647 MR9, and all versions after 9.00.
Affected products
- Gallagher Command Centre Server 9.40 prior to 9.40.1976 MR1, 9.30 prior to 9.30.3382 MR4, 9.20 prior to 9.20.3783 MR6, 9.10 prior to 9.10.4647 MR9, 9.00 and all prior versions
Timeline
- 2026-03-03: disclosed