CVE-2026-25193
EUVD-2026-3163625.05.2026, 07:16
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted. Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gallagher | active_directory_sync | 𝑥 < 9.10.05 |
| gallagher | cardholder_sync_utility | 𝑥 < 9.30.104 |
| gallagher | command_centre | 𝑥 < 9.40.2575 |
| gallagher | diagnostics_service | 𝑥 < 2.0.9 |
| gallagher | elevator_service | 𝑥 < 10.0.8 |
| gallagher | encoding_kiosk_application | 𝑥 < 9.60.10 |
| gallagher | entra_id_sync_v1 | 𝑥 < 1.0.10 |
| gallagher | entra_id_sync_v2 | 𝑥 < 2.0.5 |
| gallagher | event_logger | 𝑥 < 8.90.16 |
| gallagher | event_sync_utility | 𝑥 < 8.70.62 |
| gallagher | middleware_framework | 𝑥 < 8.90.34 |
| gallagher | nexudus_integration | 𝑥 < 9.60.21 |
| gallagher | okta_sync | 𝑥 < 9.40.05 |
| gallagher | papercut_interface_integration | 𝑥 < 9.60.02 |
| gallagher | sip_integration | 𝑥 < 10.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration