PT-2026-43004 · Gallagher · Command Centre Server

CVE-2026-25193

·

Published

2026-05-25

·

Updated

2026-08-17

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Command Centre Service (affected versions not specified)
Description Some installers for the Command Centre Service improperly insert sensitive information into log files. This issue can lead to the exposure of service account credentials. This specifically impacts sites that use a custom service account rather than the default network service account.
Recommendations Change the password for the custom service account. Delete installer log files located in %programdata%GallagherCommand Centre.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25193

Affected Products

Command Centre Server