CVE-2026-25193: Gallagher Active Directory Sync
High severity, CVSS 8.6. EPSS: 0.1% chance of exploitation in the next 30 days.
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted. Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.
Affected products
- Gallagher Active Directory Sync: before 9.10.05 (fixed in 9.10.05)
- Gallagher Cardholder Sync Utility: before 9.30.104 (fixed in 9.30.104)
- Gallagher Command Centre: before 9.40.2575 (fixed in 9.40.2575)
- Gallagher Diagnostics Service: before 2.0.9 (fixed in 2.0.9)
- Gallagher Elevator Service: before 10.0.8 (fixed in 10.0.8)
- Gallagher Encoding Kiosk Application: before 9.60.10 (fixed in 9.60.10)
- Gallagher Entra Id Sync v1: before 1.0.10 (fixed in 1.0.10)
- Gallagher Entra Id Sync v2: before 2.0.5 (fixed in 2.0.5)
- Gallagher Event Logger: before 8.90.16 (fixed in 8.90.16)
- Gallagher Event Sync Utility: before 8.70.62 (fixed in 8.70.62)
- Gallagher Middleware Framework: before 8.90.34 (fixed in 8.90.34)
- Gallagher Nexudus Integration: before 9.60.21 (fixed in 9.60.21)
- Gallagher Okta Sync: before 9.40.05 (fixed in 9.40.05)
- Gallagher PaperCut Interface Integration: before 9.60.02 (fixed in 9.60.02)
- Gallagher SIP Integration: before 10.10 (fixed in 10.10)
Published 2026-05-25. Last modified 2026-08-17.