By vendor
Gallagher vulnerabilities
Known CVEs affecting Gallagher products, prioritized by severity, with SEC.co remediation and detection guidance.
2 published vulnerabilities
- CVE-2026-27790LOW 2.7
CVE-2026-27790 is a low-severity vulnerability affecting Gallagher Command Centre and its T20 reader hardware. An authenticated operator with proper authorization can send crafted requests to trigger an unhandled exception that forces the T20 Readers to restart, causing temporary unavailability. Because it requires valid credentials and administrator-level access to exploit, the practical risk is contained, but the impact in access control environments where reader downtime disrupts operations should not be dismissed.
- CVE-2026-27844LOW 2.7
A flaw in Gallagher's Command Centre diagnostic web interface allows an authenticated operator to restart the Controller 6000 or Controller 7000 by sending specially crafted requests. This causes temporary unavailability of access control functions. The vulnerability requires valid credentials and high-level operator privileges, limiting real-world exposure. Affected versions span from 9.10 and earlier through 9.50, though multiple maintenance releases have introduced patches.