Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.
Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 26 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gallagher
Gallagher active Directory Sync Gallagher cardholder Sync Utility Gallagher command Centre Gallagher diagnostics Service Gallagher elevator Service Gallagher encoding Kiosk Application Gallagher entra Id Sync Gallagher event Logger Gallagher event Sync Utility Gallagher middleware Framework Gallagher nexudus Integration Gallagher okta Sync Gallagher papercut Interface Integration Gallagher sip Integration |
|
| Vendors & Products |
Gallagher
Gallagher active Directory Sync Gallagher cardholder Sync Utility Gallagher command Centre Gallagher diagnostics Service Gallagher elevator Service Gallagher encoding Kiosk Application Gallagher entra Id Sync Gallagher event Logger Gallagher event Sync Utility Gallagher middleware Framework Gallagher nexudus Integration Gallagher okta Sync Gallagher papercut Interface Integration Gallagher sip Integration |
Mon, 25 May 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Sensitive Information Disclosure via Installer Log Files in Gallagher Command Centre Services |
Mon, 25 May 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted. Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre. | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
Status: PUBLISHED
Assigner: Gallagher
Published:
Updated: 2026-05-26T14:24:08.348Z
Reserved: 2026-03-01T23:45:09.705Z
Link: CVE-2026-25193
Updated: 2026-05-26T14:24:05.451Z
Status : Awaiting Analysis
Published: 2026-05-25T07:16:14.263
Modified: 2026-06-17T10:24:17.233
Link: CVE-2026-25193
No data.
OpenCVE Enrichment
Updated: 2026-05-25T11:33:02Z