CVE-2026-25193
8.6
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 6.0
Source: NVD
Description
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.
Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.
Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.
Affected (15)
Products: Gallagher: Active Directory Sync, Cardholder Sync Utility, Command Centre, Diagnostics Service, Elevator Service, Encoding Kiosk Application, Entra Id Sync V1, Entra Id Sync V2, Event Logger, Event Sync Utility, Middleware Framework, Nexudus Integration, Okta Sync, Papercut Interface Integration, Sip Integration
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.10.05 | |
| Before 9.30.104 | |
| Before 9.40.2575 | |
| Before 2.0.9 | |
| Before 10.0.8 | |
| Before 9.60.10 | |
| Before 1.0.10 | |
| Before 2.0.5 | |
| Before 8.90.16 | |
| Before 8.70.62 | |
| Before 8.90.34 | |
| Before 9.60.21 | |
| Before 9.40.05 | |
| Before 9.60.02 | |
| Before 10.10 |
References (1)
Source: disclosures@gallagher.com
Vendor Advisory
Timeline
No history available yet.