Sensitive Information Exposure in Gallagher Command Centre Services Installers
CVE-2026-25193

8.1HIGH

What is CVE-2026-25193?

A vulnerability in the Gallagher Command Centre Services installers can lead to the exposure of service account credentials due to sensitive information being logged improperly. This issue primarily affects sites that use a custom service account instead of the default Network Service account. To mitigate potential risks, users are advised to change the service account password and remove installer log files, typically located in %programdata%\Gallagher\Command Centre.

Affected Version(s)

Active Directory Sync 0

Cardholder Sync Utility 0

Command Centre Server 9.40 < 9.40.2575 (MR2)

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.