CVE-2026-25193
Analyzed
Analyzed - Analysis Complete
Gallagher Command Centre Service Account Credentials Exposure via Log Files
Vulnerability report for CVE-2026-25193, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-05-25
Last updated on: 2026-08-17
Assigner: Gallagher Group Ltd.
Description
Description
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.
Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.
Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| gallagher | active_directory_sync | to 9.10.05 (exc) |
| gallagher | cardholder_sync_utility | to 9.30.104 (exc) |
| gallagher | command_centre | to 9.40.2575 (exc) |
| gallagher | diagnostics_service | to 2.0.9 (exc) |
| gallagher | elevator_service | to 10.0.8 (exc) |
| gallagher | encoding_kiosk_application | to 9.60.10 (exc) |
| gallagher | entra_id_sync_v1 | to 1.0.10 (exc) |
| gallagher | entra_id_sync_v2 | to 2.0.5 (exc) |
| gallagher | event_logger | to 8.90.16 (exc) |
| gallagher | event_sync_utility | to 8.70.62 (exc) |
| gallagher | middleware_framework | to 8.90.34 (exc) |
| gallagher | nexudus_integration | to 9.60.21 (exc) |
| gallagher | okta_sync | to 9.40.05 (exc) |
| gallagher | papercut_interface_integration | to 9.60.02 (exc) |
| gallagher | sip_integration | to 10.10 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-532 | The product writes sensitive information to a log file. |