Sensitive Information Exposure in Gallagher Command Centre Services Installers
CVE-2026-25193
8.1HIGH
What is CVE-2026-25193?
A vulnerability in the Gallagher Command Centre Services installers can lead to the exposure of service account credentials due to sensitive information being logged improperly. This issue primarily affects sites that use a custom service account instead of the default Network Service account. To mitigate potential risks, users are advised to change the service account password and remove installer log files, typically located in %programdata%\Gallagher\Command Centre.
Affected Version(s)
Active Directory Sync 0
Cardholder Sync Utility 0
Command Centre Server 9.40 < 9.40.2575 (MR2)
