PatchSiren cyber security CVE debrief
CVE-2026-20801 Gallagher CVE debrief
Cleartext Transmission of Sensitive Information (CWE-319) vulnerability in Gallagher Hanwha VMS and NxWitness VMS integrations. Unprivileged users with local network access can view live video streams. Affected versions are prior to 9.10.017 for NxWitness VMS and prior to 9.10.025 for Hanwha VMS. This vulnerability allows unauthorized access to sensitive video feeds, potentially leading to privacy breaches or further exploitation. Users of these integrations should prioritize patching to mitigate this risk. Gallagher Security Advisory and official CVE record provide further context for risk assessment and mitigation planning.
- Vendor
- Gallagher
- Product
- NxWitness VMS and Hanwha VMS Integrations
- CVSS
- MEDIUM 5.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-03
- Original CVE updated
- 2026-08-17
- Advisory published
- 2026-03-03
- Advisory updated
- 2026-08-17
Who should care
Gallagher NxWitness VMS and Hanwha VMS integration users, IT teams managing local network access, security teams monitoring for sensitive information exposure, and operators of affected systems should be aware of this vulnerability. They need to assess their current configurations, verify version numbers, and plan for immediate patching or apply compensating controls to restrict access to sensitive areas of the network. Monitoring for suspicious activity and reviewing system logs are also recommended to detect potential exploitation attempts.
Technical summary
CVE-2026-20801 is a Cleartext Transmission of Sensitive Information vulnerability in Gallagher Hanwha VMS and NxWitness VMS integrations. Unprivileged users with local network access can view live video streams. Affected versions are prior to 9.10.017 for NxWitness VMS and prior to 9.10.025 for Hanwha VMS. This vulnerability allows unauthorized access to sensitive video feeds, potentially leading to privacy breaches or further exploitation. Users of these integrations should prioritize patching to mitigate this risk.
Defensive priority
Medium-priority vulnerability in Gallagher integrations, requiring timely patching.
Recommended defensive actions
- Patch Gallagher Hanwha VMS integration to version 9.10.025 or later
- Patch Gallagher NxWitness VMS integration to version 9.10.017 or later
- Restrict local network access to sensitive areas
- Monitor for suspicious local network activity
- Verify integration versions in inventory
Evidence notes
Evidence from official CVE and NVD sources indicates Cleartext Transmission of Sensitive Information in Gallagher Hanwha VMS and NxWitness VMS integrations. Local network access required for exploitation. The issue affects Gallagher NxWitness VMS integration prior to 9.10.017 and Gallagher Hanwha VMS integration prior to 9.10.025. Users should verify their current versions and patch levels to assess exposure. Official advisories and CVE details provide further context for risk assessment and mitigation planning.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-20801 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-20801
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-20801 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20801
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2026-20801
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.