PT-2026-43004 · Gallagher · Command Centre Server
CVE-2026-25193
·
Published
2026-05-25
·
Updated
2026-08-17
CVSS v3.1
8.6
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Command Centre Service (affected versions not specified)
Description
Some installers for the Command Centre Service improperly insert sensitive information into log files. This issue can lead to the exposure of service account credentials. This specifically impacts sites that use a custom service account rather than the default network service account.
Recommendations
Change the password for the custom service account.
Delete installer log files located in
%programdata%GallagherCommand Centre.Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Command Centre Server