Gallagher
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Gallagher product.
RSS Feeds for Gallagher security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Gallagher products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Gallagher Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 7 vulnerabilities in Gallagher with an average score of 4.7 out of ten. Last year, in 2025 Gallagher had 8 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Gallagher in 2026 could surpass last years number. Last year, the average CVE base score was greater by 1.21
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 7 | 4.66 |
| 2025 | 8 | 5.86 |
| 2024 | 3 | 5.95 |
| 2023 | 8 | 6.08 |
| 2022 | 1 | 5.50 |
| 2021 | 13 | 6.65 |
| 2020 | 12 | 7.82 |
| 2019 | 2 | 0.00 |
It may take a day or so for new Gallagher vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Gallagher Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-27844 | Jul 07, 2026 |
Command Centre pre vCR9.*.260616a: Auth Operator Restarts 6000/7000 (DoS)Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: * 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1)) * 9.40 prior to vCR9.40.260616a (distributed in 9.40.3130(MR3)) * 9.30 prior to vCR9.30.260616a (distributed in 9.30.3983(MR5)) * 9.20 prior to vCR9.20.260616a (distributed in 9.20.4349(MR7)) * all versions of 9.10 and prior. |
|
| CVE-2026-27790 | Jul 07, 2026 |
Gallagher Command Centre 9.50 DoS via T20 Reader RestartUncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: * 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1)) * 9.40 prior to vCR9.40.260616a (distributed in 9.40.3130(MR3)) * 9.30 prior to vCR9.30.260616a (distributed in 9.30.3983(MR5)) * 9.20 prior to vCR9.20.260616a (distributed in 9.20.4349(MR7)) * all versions of 9.10 and prior. |
|
| CVE-2026-26053 | Jul 07, 2026 |
Gallagher Command Centre Server <=9.50.1587: Privilege Escalation (CWE-266)An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would not normally be authorized to perform. Version of Command Centre affected: 9.50 prior to vEL9.50.1587(MR1), 9.40 prior to vEL9.40.3130(MR3), 9.30 prior to vEL9.30.3983(MR5), 9.20 prior to vEL9.20.4349(MR7), all versions of 9.10. |
|
| CVE-2026-25193 | May 25, 2026 |
Gallagher CommandCentre Service Leaks ServiceAccount Credentials to Log FilesInsertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted. Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre. |
|
| CVE-2026-20801 | Mar 03, 2026 |
Cleartext Tx Enables Unprivileged View in Gallagher VMS Integrations <9.10.017/025Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations allows unprivileged users with local network access to view live video streams. This issue affects all versions of Gallagher NxWitness VMS integration prior to 9.10.017 and Gallagher Hanwha VMS integration prior to 9.10.025. |
|
| CVE-2026-20757 | Mar 03, 2026 |
Gallagher Command Centre Server < vEL9.40.1976 Improper Locking DoS (CWE-667)Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server. This issue affects Command Centre Server: 9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vEL9.20.3783 (MR6), 9.10 prior to vEL9.10.4647 (MR9), all versions of 9.00 and prior. |
|
| CVE-2025-47147 | Mar 03, 2026 |
Command Centre Mobile Client: Cleartext Session Token (CWE-312) before 9.40.123Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration. This issue affects Command Centre Mobile Client versions prior to 9.40.123. |
|
| CVE-2025-64734 | Nov 18, 2025 |
Command Centre Server v<=9.30 Missing Resource Release Allows Physical DoSMissing Release of Resource after Effective Lifetime (CWE-772) in the T21 Reader allows an attacker with physical access to the Reader to perform a denial-of-service attack against that specific reader, preventing cardholders from badging for entry. This issue affects Command Centre Server: 9.30 prior to vCR9.30.251028a (distributed in 9.30.2881 (MR3)), 9.20 prior to vCR9.20.251028a (distributed in 9.20.3265 (MR5)), 9.10 prior to vCR9.10.251028a (distributed in 9.10.4135 (MR8)), all versions of 9.00 and prior. |
|
| CVE-2025-52578 | Nov 18, 2025 |
High Sec ELM Command Centre Server PRNG Seed CVE-2025-52578 (v<9.30.251028)Incorrect Usage of Seeds in Pseudo-Random Number Generator (CWE- 335) vulnerability in the High Sec ELM may allow a sophisticated attacker with physical access, to compromise internal device communications. This issue affects Command Centre Server: 9.30 prior to vCR9.30.251028a (distributed in 9.30.2881 (MR3)), 9.20 prior to vCR9.20.251028a (distributed in 9.20.3265 (MR5)), 9.10 prior to vCR9.10.251028a (distributed in 9.10.4135 (MR8)), all versions of 9.00 and prior. |
|
| CVE-2025-52457 | Nov 18, 2025 |
HBUS Timing Leak via Command Centre Server <CR9.30.251028aObservable Timing Discrepancy (CWE-208) in HBUS devices may allow an attacker with physical access to the device to extract device-specific keys, potentially compromising further site security. This issue affects Command Centre Server: 9.30 prior to vCR9.30.251028a (distributed in 9.30.2881 (MR3)), 9.20 prior to vCR9.20.251028a (distributed in 9.20.3265 (MR5)), 9.10 prior to vCR9.10.251028a (distributed in 9.10.4135 (MR8)), all versions of 9.00 and prior. |