LOW 2.7

CVE-2026-27790: Gallagher T20 Reader Denial of Service Vulnerability Analysis

CVE-2026-27790 is a low-severity vulnerability affecting Gallagher Command Centre and its T20 reader hardware. An authenticated operator with proper authorization can send crafted requests to trigger an unhandled exception that forces the T20 Readers to restart, causing temporary unavailability. Because it requires valid credentials and administrator-level access to exploit, the practical risk is contained, but the impact in access control environments where reader downtime disrupts operations should not be dismissed.

Source data · NVD / CISA · public domain

CVSS
3.1 · 2.7 LOW · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Weaknesses (CWE)
CWE-248
Affected products
6 configuration(s)
Published / Modified
2026-07-07 / 2026-08-14

NVD description (verbatim)

Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: * 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1)) * 9.40 prior to vCR9.40.260616a (distributed in 9.40.3130(MR3)) * 9.30 prior to vCR9.30.260616a (distributed in 9.30.3983(MR5)) * 9.20 prior to vCR9.20.260616a (distributed in 9.20.4349(MR7)) * all versions of 9.10 and prior.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

The vulnerability stems from an uncaught exception (CWE-248) in T20 Reader firmware when processing specific authenticated requests. The exception condition is not properly handled, leading to a restart of the reader device. The CVSS 3.1 vector (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L) reflects that network reachability combined with high-privilege authentication is required; there is no confidentiality or integrity impact, only temporary availability loss. Multiple Command Centre versions are affected, with patch versions distributed through maintenance releases as indicated in the vendor advisory.

Business impact

In physical access control deployments, T20 Readers serve critical functions authenticating personnel and controlling door/gate systems. Restarting a reader introduces a window—potentially minutes—where badge access is unavailable, affecting employee mobility and potentially disrupting secure area workflows. Repeated exploitation could degrade operational continuity. The risk is lower than a network-wide outage because it targets individual readers and requires privileged access; however, in high-security or multi-facility environments, even brief localized downtime may warrant attention.

Affected systems

Gallagher Command Centre versions 9.50 (prior to vCR9.50.260616a), 9.40 (prior to vCR9.40.260616a), 9.30 (prior to vCR9.30.260616a), 9.20 (prior to vCR9.20.260616a), and all 9.10 and earlier versions are vulnerable. The vulnerability also affects associated T20 hardware: High Sec T20 Reader, High Sec T20 Reader Multi Tech, T20 Alarms Terminal, T20 Mifare Terminal, and T20 Multi Tech Terminal. Patches are distributed within maintenance releases (MR1, MR3, MR5, MR7 for the respective major versions).

Exploitability

Exploitability is limited by authentication and authorization requirements. An attacker must either be a legitimate operator with valid credentials or compromise an operator account. There is no evidence of widespread, weaponized exploitation (the vulnerability is not tracked on CISA's Known Exploited Vulnerabilities catalog). The attack requires network access to the Command Centre or reader management interface and cannot be executed by unauthenticated users. Once authenticated, triggering the restart is straightforward if the specific request pattern is known, but access control reduces real-world attack surface.

Remediation

Apply the patched versions as distributed in the maintenance releases: 9.50.1587(MR1), 9.40.3130(MR3), 9.30.3983(MR5), or 9.20.4349(MR7). Organizations running 9.10 and earlier should upgrade to a supported version, as no patches are issued for end-of-life releases. Test patches in a staging environment before production deployment to ensure compatibility with existing access control policies and third-party integrations.

Patch guidance

Gallagher provides patches through maintenance release channels. Verify the exact patch build numbers (vCR9.X.260616a) against Gallagher's security advisory and release notes to confirm you are applying the correct update. Plan deployment during low-traffic windows to minimize disruption if a reader requires restart during the patching process. After patching, validate T20 Reader connectivity and conduct a brief operational test to confirm badge readers respond as expected.

Detection guidance

Monitor Command Centre logs for unexpected T20 Reader restart events, particularly those correlating with administrative or operator activity. Check for unusual authentication patterns or operator account activity that might indicate credential compromise. Review access logs for operators with elevated permissions who initiated uncommon command sequences. Physical inspection of access logs (badge swipe attempts) around reader downtime events may reveal if outages coincided with suspicious activity. Network-based detection is challenging given the requirement for valid authentication; focus on behavioral anomalies and log correlation.

Why prioritize this

Although the CVSS score is low (2.7), prioritization depends on your threat model. If insider threat or operator account compromise is a concern, elevate priority. If your T20 Reader network includes critical access points (data centers, secure facilities), even brief downtime is operationally significant. Conversely, if readers control low-criticality areas and operator access is tightly controlled with strong authentication, this can be scheduled alongside regular maintenance windows. The lack of KEV designation and public exploit code supports deferring this patch if higher-risk vulnerabilities demand immediate attention, but do not neglect it long-term.

Risk score, explained

The CVSS 3.1 low score (2.7) reflects the combination of network attack vector, low attack complexity, and high privilege requirement. Because only an authenticated, authorized operator can trigger the restart and only availability is affected—not confidentiality or integrity—the intrinsic risk is modest. However, context matters: in a zero-trust environment where operator compromise is considered unlikely, risk is truly low; in a setting with weaker identity controls or higher insider threat concern, the practical risk could be elevated. Apply organizational risk tolerance and threat modeling to determine actual priority.

Frequently asked questions

Can an unauthenticated attacker restart a T20 Reader?

No. The vulnerability requires valid authentication and high-level authorization. Unauthenticated users cannot exploit this issue. An attacker would need to either compromise or impersonate an operator account.

How long does a T20 Reader stay offline after a restart?

The vulnerability description indicates a temporary denial of service; typical reader restart times are on the order of seconds to a few minutes depending on hardware initialization. Exact recovery time is not specified in the advisory and should be confirmed with Gallagher technical documentation or through lab testing.

Do all Gallagher access control systems use T20 Readers?

No. T20 is one reader model in Gallagher's portfolio. If your environment uses different reader hardware (e.g., HID, Nedap, or other integrations), you may not be affected. Verify your deployed reader types against the vendor product list to determine exposure.

Is there a workaround if we cannot patch immediately?

Limit administrative and operator access to Command Centre interfaces through network segmentation, MFA, and role-based access controls. Monitor operator activity and authentication logs for anomalies. However, these are compensating controls only; patching is the definitive fix and should be prioritized within your maintenance schedule.

This analysis is provided for informational purposes to support security decision-making. SEC.co does not produce or distribute patches; obtain all updates directly from Gallagher's official security advisories and vendor channels. CVSS scores are sourced from published CVE records and reflect standardized severity assessment but do not account for organizational context, threat landscape, or business criticality. Risk prioritization should incorporate your specific environment, threat modeling, and operational dependencies. No information in this analysis should be construed as legal advice or a guarantee of security. Organizations are responsible for validating patch compatibility and testing before production deployment. Source: NVD (public-domain), retrieved 2026-08-15. Analysis generated by SEC.co (claude-haiku-4-5).