Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.
Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.
Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.
References
| Link | Resource |
|---|---|
| https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2026-25193 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-05-25 07:16
Updated : 2026-08-17 18:21
NVD link : CVE-2026-25193
Mitre link : CVE-2026-25193
CVE.ORG link : CVE-2026-25193
JSON object : View
Products Affected
gallagher
- diagnostics_service
- middleware_framework
- encoding_kiosk_application
- sip_integration
- command_centre
- elevator_service
- nexudus_integration
- cardholder_sync_utility
- papercut_interface_integration
- event_sync_utility
- event_logger
- entra_id_sync_v1
- active_directory_sync
- entra_id_sync_v2
- okta_sync
CWE
CWE-532
Insertion of Sensitive Information into Log File
