Junglewise Threat Intelligence

CVE-2026-27790: Gallagher T20 Readers uncaught exception denial of service

CVE-2026-27790 · Severity: low · CVSS 2.7 · Published 2026-07-07

Vendors: Gallagher.

Executive brief

Gallagher T20 Readers, which are hardware devices used for secure facility access control, are vulnerable to a temporary service disruption. An authorized operator with high-level permissions can send specific requests that cause the reader to restart. This results in a temporary denial of service where the reader may be unavailable for processing access requests during the reboot cycle.

Technical details

A vulnerability classified as an Uncaught Exception (CWE-248) exists in Gallagher T20 Readers managed by Command Centre. The flaw is triggered when an authenticated and authorized operator sends specific requests to the device, causing the software to crash and the hardware to restart. This attack requires high privileges (PR:H) and is reachable over the network. The primary impact is a temporary denial of service (DoS) while the reader reboots. Gallagher recommends disabling the diagnostic web interface via DIP switch settings and software configuration as a mitigation, as this interface is the primary vector for these requests.

Affected products

  • Gallagher T20 Readers 9.50 prior to vCR9.50.260616a; 9.40 prior to vCR9.40.260616a; 9.30 prior to vCR9.30.260616a; 9.20 prior to vCR9.20.260616a; all versions of 9.10 and prior

Timeline

  • 2026-07-07: disclosed
  • 2026-07-07: advisory

References