HIGH · 8.1

CVE-2026-25193

Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.  Mitigating Factor: Only sites that install Com...

Vulnerability Description

Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.  Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted. Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GallagherActive Directory Sync< 9.10.05
GallagherCardholder Sync Utility< 9.30.104
GallagherCommand Centre< 9.40.2575
GallagherDiagnostics Service< 2.0.9
GallagherElevator Service< 10.0.8
GallagherEncoding Kiosk Application< 9.60.10
GallagherEntra Id Sync V1< 1.0.10
GallagherEntra Id Sync V2< 2.0.5
GallagherEvent Logger< 8.90.16
GallagherEvent Sync Utility< 8.70.62
GallagherMiddleware Framework< 8.90.34
GallagherNexudus Integration< 9.60.21
GallagherOkta Sync< 9.40.05
GallagherPapercut Interface Integration< 9.60.02
GallagherSip Integration< 10.10

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-25193?

CVE-2026-25193 is a vulnerability with a CVSS score of 8.1 (HIGH). Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.  Mitigating Factor: Only sites that install Com...

How severe is CVE-2026-25193?

CVE-2026-25193 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-25193?

Check the references section above for vendor advisories and patch information. Affected products include: Gallagher Active Directory Sync, Gallagher Cardholder Sync Utility, Gallagher Command Centre, Gallagher Diagnostics Service, Gallagher Elevator Service.