Review reviewHigh

CVE-2026-25193

Gallagher Command Centre Server, Active Directory Sync, Cardholder Sync Utility

Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted. Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.

CVSS
8.1
EPSS
0.13%
3.15% percentile
CISA KEV
Not listed
Published
2026.05.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.13%
Technical severityCVSS 8.1

Vulnerability overview

Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted. Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.

Affected product and versions

Product
Gallagher Command Centre Server, Active Directory Sync, Cardholder Sync Utility
Affected versions
>= 9.40 < 9.40.2575 (MR2), < 9.10.05, < 9.30.104, < 2.0.9, < 10.0.8, < 9.60.10, >= 1.0 < 1.0.10, >= 2.0 < 2.0.5, < 8.70.62, < 8.90.16, < 8.90.34, < 9.60.21, < 9.40.05, < 9.60.02, < 10.1.0
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Gallagher Command Centre Server, Active Directory Sync, Cardholder Sync Utility and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H
CWE
CWE-532
CVE-2026-25193 — Gallagher Command Centre Server, Active Directory Sync, Cardholder Sync Utility | SECUFOCUS NOW