CVE-2026-25193
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted. Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.
Published:May 25, 2026
Last Modified:Aug 17, 2026
EPS:May 25, 2026
EPSS Score:0.00132
CVSS Score:8.1
Affected Products
Vendor
Product
Action
Vendor
Gallagher
Product
Active Directory Sync
Gallagher
Active Directory Sync
Vendor
Gallagher
Product
Cardholder Sync Utility
Gallagher
Cardholder Sync Utility
Vendor
Gallagher
Product
Command Centre
Gallagher
Command Centre
Vendor
Gallagher
Product
Diagnostics Service
Gallagher
Diagnostics Service
Vendor
Gallagher
Product
Elevator Service
Gallagher
Elevator Service
Vendor
Gallagher
Product
Encoding Kiosk Application
Gallagher
Encoding Kiosk Application
Vendor
Gallagher
Product
Entra Id Sync
Gallagher
Entra Id Sync
Vendor
Gallagher
Product
Entra Id Sync V1
Gallagher
Entra Id Sync V1
Vendor
Gallagher
Product
Entra Id Sync V2
Gallagher
Entra Id Sync V2
Vendor
Gallagher
Product
Event Logger
Gallagher
Event Logger
Vendor
Gallagher
Product
Event Sync Utility
Gallagher
Event Sync Utility
Vendor
Gallagher
Product
Middleware Framework
Gallagher
Middleware Framework
Vendor
Gallagher
Product
Nexudus Integration
Gallagher
Nexudus Integration
Vendor
Gallagher
Product
Okta Sync
Gallagher
Okta Sync
Vendor
Gallagher
Product
Papercut Interface Integration
Gallagher
Papercut Interface Integration
Vendor
Gallagher
Product
Sip Integration
Gallagher
Sip Integration
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
