CVE-2026-27844Disclosure(gallagher / command_centre)

LOWCVSS 2.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denial of service.  Version of Command Centre affected: * 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1)) * 9.40 prior to vCR9.40.260616a (distributed in 9.40.3130(MR3)) * 9.30 prior to vCR9.30.260616a (distributed in 9.30.3983(MR5)) * 9.20 prior to vCR9.20.260616a (distributed in 9.20.4349(MR7)) * all versions of 9.10 and prior.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-248

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • command_centre
  • controller_6000
  • controller_7000
  • controller_7000_enhanced

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-07-07); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
command_centrecontroller_6000controller_7000controller_7000_enhancedcontroller_7000_high_securitycontroller_7000_single_doorcontroller_7000_two_door

1 version affected across 7 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-07: 1Mentions · 2026-08-17: 1Technical Details · 2026-07-07: 1Technical Details · 2026-08-17: 107-0708-17
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🔵 Gallagher Command Centre Controller 6000/7000, Uncaught Exception Denial of Service, #CVE-2026-27844 (Low) -DC-Aug2026-1521 https://dailycve.com/gallagher-command-centre-controller-6000-7000-uncaught-exception-denial-of-service-cve-2026-27844-low-dc-aug2026-1521/

    Post summary

    A new CVE (CVE‑2026‑27844) affecting Gallagher Command Centre Controller 6000/7000 is disclosed as an uncaught‑exception Denial of Service, with no PoC, exploit, or patch details provided.

    0000028
    228 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27844 Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controll… https://www.cve.org/CVERecord?id=CVE-2026-27844

    Post summary

    A brief CVE record description points out an uncaught exception in certain diagnostic web interfaces accessible to authenticated operators, but offers no evidence of PoC, exploitation, or mitigation.

    00000699
    57.8K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appgallaghercommand_centre---
HWgallaghercontroller_6000---
HWgallaghercontroller_7000---
HWgallaghercontroller_7000_enhanced---
HWgallaghercontroller_7000_high_security---
HWgallaghercontroller_7000_single_door---
HWgallaghercontroller_7000_two_door---

Explore more