Executive brief
Gallagher Command Centre, a security management platform used for access control and site security, contains a vulnerability that allows authorized users to exceed their assigned permissions. An operator with limited access could perform unauthorized actions within the system, potentially compromising the integrity of security operations. This issue affects various versions of the Command Centre Server software, and updates are available to resolve the flaw.
Technical details
An Incorrect Privilege Assignment (CWE-266) exists in the Gallagher Command Centre Server. The vulnerability allows a remote, authenticated operator with low privileges to bypass intended authorization checks and perform operations they are not normally permitted to execute. The attack complexity is rated as high, suggesting specific conditions or configurations must be met to successfully exploit the flaw. The impact is primarily on system integrity, as unauthorized changes can be made to the server's operations. Patches have been released for versions 9.20 through 9.50, while version 9.10 remains fully affected.
Affected products
- Gallagher Command Centre Server 9.50 prior to vEL9.50.1587(MR1), 9.40 prior to vEL9.40.3130(MR3), 9.30 prior to vEL9.30.3983(MR5), 9.20 prior to vEL9.20.4349(MR7), all versions of 9.10
Timeline
- 2026-07-07: disclosed
- 2026-07-07: advisory