Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.
Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.
Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.
Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.
Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Gallagher
Subscribe
|
Active Directory Sync
Subscribe
Cardholder Sync Utility
Subscribe
Command Centre
Subscribe
Diagnostics Service
Subscribe
Elevator Service
Subscribe
Encoding Kiosk Application
Subscribe
Entra Id Sync
Subscribe
Event Logger
Subscribe
Event Sync Utility
Subscribe
Middleware Framework
Subscribe
Nexudus Integration
Subscribe
Okta Sync
Subscribe
Papercut Interface Integration
Subscribe
Sip Integration
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 25 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gallagher
Gallagher active Directory Sync Gallagher cardholder Sync Utility Gallagher command Centre Gallagher diagnostics Service Gallagher elevator Service Gallagher encoding Kiosk Application Gallagher entra Id Sync Gallagher event Logger Gallagher event Sync Utility Gallagher middleware Framework Gallagher nexudus Integration Gallagher okta Sync Gallagher papercut Interface Integration Gallagher sip Integration |
|
| Vendors & Products |
Gallagher
Gallagher active Directory Sync Gallagher cardholder Sync Utility Gallagher command Centre Gallagher diagnostics Service Gallagher elevator Service Gallagher encoding Kiosk Application Gallagher entra Id Sync Gallagher event Logger Gallagher event Sync Utility Gallagher middleware Framework Gallagher nexudus Integration Gallagher okta Sync Gallagher papercut Interface Integration Gallagher sip Integration |
Mon, 25 May 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Sensitive Information Disclosure via Installer Log Files in Gallagher Command Centre Services |
Mon, 25 May 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted. Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre. | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Gallagher
Published:
Updated: 2026-05-25T05:28:14.766Z
Reserved: 2026-03-01T23:45:09.705Z
Link: CVE-2026-25193
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-25T11:33:02Z
Weaknesses