PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-25193 Gallagher CVE debrief

CVE-2026-25193 is a HIGH severity vulnerability (CVSS 8.1) involving insertion of sensitive information into log files (CWE-532) in Gallagher Command Centre Service installers. The issue was published on 2026-05-25 and last modified on 2026-05-26. When administrators install Command Centre Services using a custom Service Account rather than the default Network Service account, the installer may write Service Account credentials to log files, potentially exposing them to local attackers with file system access. The vulnerability requires local access, low attack complexity, and low privileges, but has a significant impact on confidentiality, integrity, and availability when chained with other attack vectors. Gallagher has identified this issue and provided mitigation guidance. The scope of impact is limited to environments with custom Service Account configurations.

Vendor
Gallagher
Product
Command Centre Server
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-25
Original CVE updated
2026-05-26
Advisory published
2026-05-25
Advisory updated
2026-05-26

Who should care

System administrators managing Gallagher Command Centre deployments, security teams responsible for credential management and privilege access, and organizations using custom Service Accounts for Command Centre Services should prioritize assessment and mitigation. This vulnerability is particularly relevant for enterprises with strict credential rotation policies and those subject to compliance requirements for privileged access management.

Technical summary

The vulnerability exists in the Command Centre Service installer where sensitive information (Service Account credentials) is written to log files during installation. This occurs specifically when administrators configure a custom Service Account instead of accepting the default Network Service account. The log files are typically created in %programdata%

Defensive priority

HIGH

Recommended defensive actions

  • Review Command Centre Service installations to identify any deployments using custom Service Accounts rather than the default Network Service account
  • For systems using custom Service Accounts, rotate the Service Account password immediately
  • Delete installer log files located in %programdata%
  • Gallagher
  • Command Centre on affected systems
  • Audit file system permissions on %programdata%
  • Gallagher directories to ensure least privilege access
  • Monitor for unauthorized access attempts to Service Account credentials or anomalous authentication patterns using these accounts

Evidence notes

The vulnerability description and mitigation guidance originate from Gallagher's security advisory ([email protected]) as referenced in NVD. CVSS 3.1 vector confirms local attack vector with scope change. The vendor field indicates 'Unknown Vendor' with low confidence and needsReview flag set to true, though the evidence points to Gallagher as the affected vendor based on reference domain candidate and security advisory URL.

Official resources

Gallagher disclosed this vulnerability through their security advisory channel on 2026-05-25, with subsequent modification on 2026-05-26. The vendor has assigned this CVE identifier and published technical details including affected product