Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-25193

8.1 · HIGH
Published May 25, 2026 gallagher CWE-532

Overview

CVE-2026-25193 is a high-severity vulnerability affecting gallagher active_directory_sync. It was published on May 25, 2026 and has a CVSS 3.1 base score of 8.1 (HIGH).

This vulnerability has a CVSS 3.1 base score of 8.1, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. 

Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.

Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.

Remediation

Check the references section for vendor advisories and patches from gallagher. Update active_directory_sync to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
gallagher active_directory_sync >= 0, < 9.10.05 Affected
gallagher cardholder_sync_utility >= 0, < 9.30.104 Affected
gallagher command_centre >= 0, < 9.40.2575 Affected
gallagher diagnostics_service >= 0, < 2.0.9 Affected
gallagher elevator_service >= 0, < 10.0.8 Affected
gallagher encoding_kiosk_application >= 0, < 9.60.10 Affected
gallagher entra_id_sync_v1 >= 0, < 1.0.10 Affected
gallagher entra_id_sync_v2 >= 0, < 2.0.5 Affected
gallagher event_logger >= 0, < 8.90.16 Affected
gallagher event_sync_utility >= 0, < 8.70.62 Affected
gallagher middleware_framework >= 0, < 8.90.34 Affected
gallagher nexudus_integration >= 0, < 9.60.21 Affected
gallagher okta_sync >= 0, < 9.40.05 Affected
gallagher papercut_interface_integration >= 0, < 9.60.02 Affected
gallagher sip_integration >= 0, < 10.10 Affected

Frequently Asked Questions

What is CVE-2026-25193?

CVE-2026-25193 is a high-severity vulnerability affecting gallagher active_directory_sync. It was published on May 25, 2026 and has a CVSS 3.1 base score of 8.1 (HIGH).

How severe is CVE-2026-25193?

This vulnerability has a CVSS 3.1 base score of 8.1, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2026-25193?

Check the references section for vendor advisories and patches from gallagher. Update active_directory_sync to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-25193?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-25193 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.

Browse by year 2026