CVE-2026-25193Disclosure(gallagher / active_directory_sync)

LOWCVSS 8.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.  Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted. Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-532

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • active_directory_sync
  • cardholder_sync_utility
  • command_centre
  • diagnostics_service

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
active_directory_synccardholder_sync_utilitycommand_centrediagnostics_serviceelevator_serviceencoding_kiosk_applicationentra_id_sync_v1entra_id_sync_v2event_loggerevent_sync_utility

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-25: 2Technical Details · 2026-05-25: 205-25
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25193 Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.  Mitigating F… https://www.cve.org/CVERecord?id=CVE-2026-25193 ----- Traducción: CVE-2026-25193 In… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-25193, describing that sensitive credentials can be logged during installation of the Command Centre Service; no exploit or patch details are given beyond a generic mitigation reference.

    0000028
    79 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25193 Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.  Mitigating F… https://www.cve.org/CVERecord?id=CVE-2026-25193

    Post summary

    The tweet announces CVE‑2026‑25193, outlining a CWE‑532 logging issue that could expose service account credentials, but provides no PoC, exploit, patch, or evidence of active exploitation.

    00000242
    57.5K followersView on X
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
Appgallagheractive_directory_sync-command_centre-
Appgallaghercardholder_sync_utility-command_centre-
Appgallaghercommand_centre---
Appgallagherdiagnostics_service-command_centre-
Appgallagherelevator_service-command_centre-
Appgallagherencoding_kiosk_application-command_centre-
Appgallagherentra_id_sync_v1-command_centre-
Appgallagherentra_id_sync_v2-command_centre-
Appgallagherevent_logger-command_centre-
Appgallagherevent_sync_utility-command_centre-
Appgallaghermiddleware_framework-command_centre-
Appgallaghernexudus_integration-command_centre-
Appgallagherokta_sync-command_centre-
Appgallagherpapercut_interface_integration-command_centre-
Appgallaghersip_integration-command_centre-

Explore more