CVE-2026-25193: Gallagher Active Directory Sync

High severity, CVSS 8.6. EPSS: 0.1% chance of exploitation in the next 30 days.

Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.  Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted. Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.

Affected products

  • Gallagher Active Directory Sync: before 9.10.05 (fixed in 9.10.05)
  • Gallagher Cardholder Sync Utility: before 9.30.104 (fixed in 9.30.104)
  • Gallagher Command Centre: before 9.40.2575 (fixed in 9.40.2575)
  • Gallagher Diagnostics Service: before 2.0.9 (fixed in 2.0.9)
  • Gallagher Elevator Service: before 10.0.8 (fixed in 10.0.8)
  • Gallagher Encoding Kiosk Application: before 9.60.10 (fixed in 9.60.10)
  • Gallagher Entra Id Sync v1: before 1.0.10 (fixed in 1.0.10)
  • Gallagher Entra Id Sync v2: before 2.0.5 (fixed in 2.0.5)
  • Gallagher Event Logger: before 8.90.16 (fixed in 8.90.16)
  • Gallagher Event Sync Utility: before 8.70.62 (fixed in 8.70.62)
  • Gallagher Middleware Framework: before 8.90.34 (fixed in 8.90.34)
  • Gallagher Nexudus Integration: before 9.60.21 (fixed in 9.60.21)
  • Gallagher Okta Sync: before 9.40.05 (fixed in 9.40.05)
  • Gallagher PaperCut Interface Integration: before 9.60.02 (fixed in 9.60.02)
  • Gallagher SIP Integration: before 10.10 (fixed in 10.10)

Published 2026-05-25. Last modified 2026-08-17.