Junglewise Threat Intelligence

CVE-2026-25193: Gallagher Command Centre credential exposure in service installers

CVE-2026-25193 · Severity: high · CVSS 8.1 · Published 2026-05-25

Technologies: Gallagher Command Centre Server. Vendors: Gallagher.

Executive brief

Gallagher Command Centre, a security management platform used for access control and perimeter security, contains a vulnerability where installers may record sensitive service account passwords in plain text within log files. If a site uses a custom service account instead of the default system account, an unauthorized person with local access to the server could discover these credentials. This could allow an attacker to gain elevated privileges, potentially compromising the security operations or sensitive data managed by the system.

Technical details

A CWE-532 (Insertion of Sensitive Information into Log File) vulnerability exists in multiple Gallagher Command Centre Service installers. When a custom Service Account is specified during installation, the installer may write the account's credentials into log files located in %programdata%\Gallagher\Command Centre. An attacker with local access and low privileges could read these logs to obtain service account credentials. This vulnerability is particularly impactful because the CVSS score reflects a scope change (S:C), indicating that the compromised credentials could allow an attacker to impact components beyond the installer itself. Patches have been released for various affected components including the Command Centre Server, Active Directory Sync, and various integration utilities.

Affected products

  • Gallagher Command Centre Server vEL9.40 before 9.40.2575 (MR2)
  • Gallagher Active Directory Sync before 9.10.05
  • Gallagher Cardholder Sync Utility before 9.30.104
  • Gallagher Diagnostics Service before 2.0.9
  • Gallagher Elevator Service before 10.0.8
  • Gallagher Encoding Kiosk Application before 9.60.10
  • Gallagher Entra ID Sync v1 before v1.0.10
  • Gallagher Entra ID Sync v2 before 2.0.5
  • Gallagher Event Sync Utility before 8.70.62
  • Gallagher Gallagher Event Logger before 8.90.16
  • Gallagher Middleware Framework before 8.90.34
  • Gallagher Nexudus Integration before 9.60.21
  • Gallagher Okta Sync before 9.40.05
  • Gallagher Papercut Interface Integration before 9.60.02
  • Gallagher SIP Integration before 10.1.0

Timeline

  • 2026-05-25: disclosed
  • 2026-05-25: advisory

References

Related threats