High severity8.1NVD Advisory· Published May 25, 2026· Updated Aug 17, 2026
CVE-2026-25193
CVE-2026-25193
Description
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.
Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16- cpe:2.3:a:gallagher:active_directory_sync:*:*:*:*:*:command_centre:*:*Range: <9.10.05
- cpe:2.3:a:gallagher:cardholder_sync_utility:*:*:*:*:*:command_centre:*:*Range: <9.30.104
- cpe:2.3:a:gallagher:diagnostics_service:*:*:*:*:*:command_centre:*:*Range: <2.0.9
- cpe:2.3:a:gallagher:elevator_service:*:*:*:*:*:command_centre:*:*Range: <10.0.8
- cpe:2.3:a:gallagher:encoding_kiosk_application:*:*:*:*:*:command_centre:*:*Range: <9.60.10
- cpe:2.3:a:gallagher:entra_id_sync_v1:*:*:*:*:*:command_centre:*:*Range: <1.0.10
- cpe:2.3:a:gallagher:entra_id_sync_v2:*:*:*:*:*:command_centre:*:*Range: <2.0.5
- cpe:2.3:a:gallagher:event_sync_utility:*:*:*:*:*:command_centre:*:*Range: <8.70.62
- cpe:2.3:a:gallagher:middleware_framework:*:*:*:*:*:command_centre:*:*Range: <8.90.34
- cpe:2.3:a:gallagher:nexudus_integration:*:*:*:*:*:command_centre:*:*Range: <9.60.21
- cpe:2.3:a:gallagher:papercut_interface_integration:*:*:*:*:*:command_centre:*:*Range: <9.60.02
- cpe:2.3:a:gallagher:sip_integration:*:*:*:*:*:command_centre:*:*Range: <10.10
Patches
Vulnerability mechanics
References
1- security.gallagher.com/en-NZ/Security-Advisories/CVE-2026-25193nvdVendor Advisory
News mentions
0No linked articles in our index yet.