← Back

CVE-2026-26053

nvd nist
Published: Jul 7, 2026Modified: Aug 18, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.6 / Impact: 3.6
Source: disclosures@gallagher.com (Secondary)

Description

An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would not normally be authorized to perform. Version of Command Centre affected: 9.50 prior to vEL9.50.1587(MR1), 9.40 prior to vEL9.40.3130(MR3), 9.30 prior to vEL9.30.3983(MR5), 9.20 prior to vEL9.20.4349(MR7), all versions of 9.10.

Affected (4)

1 product
Command Centre
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Gallagher
Before 9.20.4349
From 9.30.1594 to 9.30.3983
From 9.40.1359 to 9.40.3130
From 9.50.978 to 9.50.1587

References (1)

Source: disclosures@gallagher.com
Vendor Advisory

Timeline

No history available yet.