CVE-2026-20757: Gallagher Command Centre

Low severity, CVSS 2.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server. This issue affects Command Centre Server: 9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vEL9.20.3783 (MR6), 9.10 prior to vEL9.10.4647 (MR9), all versions of 9.00 and prior.

Affected products

  • Gallagher Command Centre: before 9.10.4647 (fixed in 9.10.4647); from 9.20.1043, before 9.20.3783 (fixed in 9.20.3783); from 9.30.1594, before 9.30.3382 (fixed in 9.30.3382); from 9.40.1359, before 9.40.1976 (fixed in 9.40.1976)

Published 2026-03-03. Last modified 2026-08-18.