← Back

CVE-2026-27790

nvd nist
Published: Jul 7, 2026Modified: Aug 14, 2026

JSON object

Loading...
2.7
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Exploitability: 1.2 / Impact: 1.4
Source: disclosures@gallagher.com (Secondary)

Description

Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: * 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1)) * 9.40 prior to vCR9.40.260616a (distributed in 9.40.3130(MR3)) * 9.30 prior to vCR9.30.260616a (distributed in 9.30.3983(MR5)) * 9.20 prior to vCR9.20.260616a (distributed in 9.20.4349(MR7)) * all versions of 9.10 and prior.

Affected (4)

1 product
Command Centre
Configuration A
4 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Gallagher
Before 9.20.4349
From 9.30.1594 to 9.30.3983
From 9.40.1359 to 9.40.3130
From 9.50.978 to 9.50.1587
Running on/withPlatform Versions
Gallagher
High Sec T20 Reader
All versions
Gallagher
High Sec T20 Reader Multi Tech
All versions
Gallagher
T20 Alarms Terminal
All versions
Gallagher
T20 Mifare Terminal
All versions
Gallagher
T20 Multi Tech Terminal
All versions

References (1)

Source: disclosures@gallagher.com
Vendor Advisory

Timeline

No history available yet.