Command centre
This hub aggregates every CVE we track for Command centre, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
43
CVEs tracked
6
Critical
15
High
0
In CISA KEV
Severity distribution
MEDIUM17HIGH15CRITICAL6LOW5
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
1
0
3
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Command centre.
- CVE-2026-27844Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific...2.7
- CVE-2026-27790Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial of service. Ve...2.7
- CVE-2026-26053An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would not ...5.3
- CVE-2026-25193Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that inst...8.1
- CVE-2026-20757Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server. This issue affects Comm...2.5
- CVE-2024-23194Improper output Neutralization for Logs (CWE-117) in the Command Centre API Diagnostics Endpoint could allow an attacker limited ability to modify Command Centre log files. This issue affects: ...3.3
- CVE-2024-21838 Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection in emails generated by Command Ce...6.8
- CVE-2024-21815 Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher...9.1
- CVE-2023-46686 A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protoc...5.5
- CVE-2023-23584 An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable. This issu...4.3
- CVE-2023-23576 Incorrect behavior order in the Command Centre Server could allow privileged users to gain physical access to the site for longer than intended after a network outage when competencies are used in...4.3
- CVE-2023-23570 Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with undefined behavior. This issue affects: Gallagher Command C...5.4
- CVE-2023-22439 Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web interface (Port 80) can be used to perform a Denial of Service of the diagno...3.1
- CVE-2023-23568 Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Personal Data Fields. This issue affects Command Centre: vEL 8.90 prior to v...4.3
- CVE-2023-22363Access Zone stack overflow6.5
Product normalization is registry-driven with AI assist and human review. How it works