CVE Database
/

CVE-2026-25193

Back to search

CVE-2026-25193

Published: May 25, 2026

Modified: May 26, 2026

PUBLISHED

CVSS v3.1

8.1

HIGH

Description

Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.  Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted. Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.

VendorProductVersions

Gallagher

Command Centre Server

affected
9.40 - < 9.40.2575 (MR2)

Gallagher

Active Directory Sync

affected
0 - < 9.10.05

Gallagher

Cardholder Sync Utility

affected
0 - < 9.30.104

Gallagher

Diagnostics Service

affected
0 - < 2.0.9

Gallagher

Elevator Service

affected
0 - < 10.0.8

Gallagher

Encoding Kiosk Application

affected
0 - < 9.60.10

Gallagher

Entra ID Sync

affected
1.0 - < 1.0.10
affected
2.0 - < 2.0.5

Gallagher

Event Sync Utility

affected
0 - < 8.70.62

Gallagher

Event Logger

affected
0 - < 8.90.16

Gallagher

Middleware Framework

affected
0 - < 8.90.34

Gallagher

Nexudus Integration

affected
0 - < 9.60.21

Gallagher

Okta Sync

affected
0 - < 9.40.05

Gallagher

Papercut Interface Integration

affected
0 - < 9.60.02

Gallagher

SIP Integration

affected
0 - < 10.1.0

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now