← All Advisories

CVE-2026-25193

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-25193

Key Details

CVECVE-2026-25193
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-08-17
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is required; scope is changed; confidentiality impact is low; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-532 (Insertion of Sensitive Information into Log File)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
GallagherCommand Centre
Gallagheractive_directory_sync
Gallaghercardholder_sync_utility
Gallagherdiagnostics_service
Gallagherelevator_service
Gallagherencoding_kiosk_application
Gallagherentra_id_sync_v1
Gallagherentra_id_sync_v2
Gallagherevent_logger
Gallagherevent_sync_utility
Gallaghermiddleware_framework
Gallaghernexudus_integration
Gallagherokta_sync
Gallagherpapercut_interface_integration
Gallaghersip_integration
GallagherCommand Centre Server
GallagherActive Directory Sync
GallagherCardholder Sync Utility
GallagherDiagnostics Service
GallagherElevator Service
GallagherEncoding Kiosk Application
GallagherEntra ID Sync
GallagherEvent Sync Utility
GallagherEvent Logger
GallagherMiddleware Framework
GallagherNexudus Integration
GallagherOkta Sync
GallagherPapercut Interface Integration
GallagherSIP Integration
SubsystemsPhysical Access & Security Systems
SectorsDefense Industrial Base, Energy, Government Facilities

What to Know

Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. 

Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.

Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre. (NVD)

What to Do

Monitor Gallagher's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-25193
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-25193
Vendor advisoryhttps://security.gallagher.com/en-NZ/Security-Advisories/CVE-2026-25193