CVE-2026-26053

EUVD-2026-42000
An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would not normally be authorized to perform. Version of Command Centre affected: 9.50 prior to vEL9.50.1587(MR1), 9.40 prior to vEL9.40.3130(MR3), 9.30 prior to vEL9.30.3983(MR5), 9.20 prior to vEL9.20.4349(MR7), all versions of 9.10.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 4.95%
Affected Products (NVD)
VendorProductVersion
gallaghercommand_centre
𝑥
< 9.20.4349
gallaghercommand_centre
9.30.1594 ≤
𝑥
< 9.30.3983
gallaghercommand_centre
9.40.1359 ≤
𝑥
< 9.40.3130
gallaghercommand_centre
9.50.978 ≤
𝑥
< 9.50.1587
𝑥
= Vulnerable software versions