Junglewise Threat Intelligence

CVE-2026-20757: Gallagher Command Centre Server improper locking in Morpho integration

CVE-2026-20757 · Severity: low · CVSS 2.5 · Published 2026-03-03

Technologies: Gallagher Command Centre Server. Vendors: Gallagher.

Executive brief

Gallagher Command Centre Server is a critical component of enterprise access control and security management systems. A locking vulnerability in the Morpho biometric integration allows a privileged operator to cause temporary unavailability of the system, potentially disrupting access control operations at a facility.

Technical details

An improper locking vulnerability (CWE-667) exists in the Gallagher Morpho biometric integration component within Command Centre Server. The vulnerability allows a user with privileged operator credentials to trigger a limited denial-of-service condition. The attack requires local access, high attack complexity, and valid operator privileges. The impact is limited to temporary availability disruption with no impact on confidentiality or integrity. Patches are available across all affected versions: 9.40.1976 MR1, 9.30.3382 MR4, 9.20.3783 MR6, 9.10.4647 MR9, and all versions after 9.00.

Affected products

  • Gallagher Command Centre Server 9.40 prior to 9.40.1976 MR1, 9.30 prior to 9.30.3382 MR4, 9.20 prior to 9.20.3783 MR6, 9.10 prior to 9.10.4647 MR9, 9.00 and all prior versions

Timeline

  • 2026-03-03: disclosed

References

Related threats