Status: UPDATED | Advisory ID: CVE-2026-25193
| CVE | CVE-2026-25193 |
| CVSS Score / Version | 8.1 (High) / CVSS v3.1 |
| Updated | 2026-08-17 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is low; user interaction is required; scope is changed; confidentiality impact is low; integrity impact is high; availability impact is high. |
| Affected products | see table below |
| Classified as | CWE-532 (Insertion of Sensitive Information into Log File) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Gallagher | Command Centre | ||
| Gallagher | active_directory_sync | ||
| Gallagher | cardholder_sync_utility | ||
| Gallagher | diagnostics_service | ||
| Gallagher | elevator_service | ||
| Gallagher | encoding_kiosk_application | ||
| Gallagher | entra_id_sync_v1 | ||
| Gallagher | entra_id_sync_v2 | ||
| Gallagher | event_logger | ||
| Gallagher | event_sync_utility | ||
| Gallagher | middleware_framework | ||
| Gallagher | nexudus_integration | ||
| Gallagher | okta_sync | ||
| Gallagher | papercut_interface_integration | ||
| Gallagher | sip_integration | ||
| Gallagher | Command Centre Server | ||
| Gallagher | Active Directory Sync | ||
| Gallagher | Cardholder Sync Utility | ||
| Gallagher | Diagnostics Service | ||
| Gallagher | Elevator Service | ||
| Gallagher | Encoding Kiosk Application | ||
| Gallagher | Entra ID Sync | ||
| Gallagher | Event Sync Utility | ||
| Gallagher | Event Logger | ||
| Gallagher | Middleware Framework | ||
| Gallagher | Nexudus Integration | ||
| Gallagher | Okta Sync | ||
| Gallagher | Papercut Interface Integration | ||
| Gallagher | SIP Integration |
| Subsystems | Physical Access & Security Systems |
| Sectors | Defense Industrial Base, Energy, Government Facilities |
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.
Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.
Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre. (NVD)
Monitor Gallagher's web page for any future patch releases. See vendor advisory link below.