LOW 2.7

CVE-2026-27844: Gallagher Command Centre Controller Restart Vulnerability

A flaw in Gallagher's Command Centre diagnostic web interface allows an authenticated operator to restart the Controller 6000 or Controller 7000 by sending specially crafted requests. This causes temporary unavailability of access control functions. The vulnerability requires valid credentials and high-level operator privileges, limiting real-world exposure. Affected versions span from 9.10 and earlier through 9.50, though multiple maintenance releases have introduced patches.

Source data · NVD / CISA · public domain

CVSS
3.1 · 2.7 LOW · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Weaknesses (CWE)
CWE-248
Affected products
7 configuration(s)
Published / Modified
2026-07-07 / 2026-08-14

NVD description (verbatim)

Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denial of service.  Version of Command Centre affected: * 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1)) * 9.40 prior to vCR9.40.260616a (distributed in 9.40.3130(MR3)) * 9.30 prior to vCR9.30.260616a (distributed in 9.30.3983(MR5)) * 9.20 prior to vCR9.20.260616a (distributed in 9.20.4349(MR7)) * all versions of 9.10 and prior.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-27844 is an uncaught exception vulnerability (CWE-248) residing in the diagnostic web interface of Gallagher Controller 6000 and Controller 7000 devices. When an authenticated operator with elevated privileges submits specific HTTP requests to the interface, the application fails to gracefully handle the input, triggering an unhandled exception that forces a controller restart. This results in a temporary denial of service affecting physical access control until the controller recovers. The vulnerability does not permit privilege escalation, data exfiltration, or unauthorized access—it strictly impacts availability.

Business impact

Organizations relying on Gallagher Command Centre for access control face temporary outages if a trusted operator—intentionally or through compromised credentials—sends malicious requests to the diagnostic interface. In high-security environments (healthcare, banking, data centers), even brief access control disruptions create compliance and safety risks. The low CVSS score reflects the authentication barrier; however, the blast radius depends on controller redundancy and failover architecture. Facilities without backup access mechanisms may experience physical security gaps during restart.

Affected systems

The vulnerability affects Gallagher Command Centre versions 9.10 and all prior releases, as well as: 9.20 before maintenance release vCR9.20.260616a (distributed in 9.20.4349 MR7); 9.30 before vCR9.30.260616a (distributed in 9.30.3983 MR5); 9.40 before vCR9.40.260616a (distributed in 9.40.3130 MR3); and 9.50 before vCR9.50.260616a (distributed in 9.50.1587 MR1). The vulnerable interface resides in Controller 6000 and Controller 7000 variants, including the 7000 Enhanced, High Security, Single Door, and Two Door models. Verify your specific build version against the Command Centre release notes to confirm patch status.

Exploitability

Exploitation requires two significant barriers: valid operator credentials and high-privilege (PR:H in CVSS terms) authorization within the Command Centre. An attacker cannot exploit this remotely without compromised credentials or insider access. The attack surface is limited to the diagnostic web interface, which should be restricted to trusted network segments. No public exploits are known, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog. Organizations with strong access controls, credential hygiene, and network segmentation will find practical exploitation unlikely.

Remediation

Upgrade Command Centre to patched maintenance releases: 9.50.1587 MR1 or later (containing vCR9.50.260616a), 9.40.3130 MR3 or later (containing vCR9.40.260616a), 9.30.3983 MR5 or later (containing vCR9.30.260616a), or 9.20.4349 MR7 or later (containing vCR9.20.260616a). Versions 9.10 and prior have no patched releases; upgrade to 9.20 or newer. Pending patching, implement network-level controls: restrict diagnostic interface access to authorized administrator workstations via firewall rules, disable remote access to the interface if not required, and audit operator privilege assignments to minimize high-privilege accounts.

Patch guidance

Consult Gallagher's official security advisory and release notes for your specific version. Patched maintenance releases introduce the fix without requiring a major version upgrade. Plan maintenance windows during low-activity periods, as restarts are involved. Test patches in a non-production environment first. Verify patch installation by confirming the exact build version matches the advisory-specified version (e.g., vCR9.50.260616a for 9.50.x lines). Document patch deployment for compliance audits.

Detection guidance

Monitor Command Centre diagnostic interface logs for unusual or repeated POST/PUT requests from authenticated users, particularly those with high-privilege accounts. Look for error patterns such as unhandled exceptions or sudden controller resets following authentication events on the diagnostic interface. Network-based detection can flag access to the diagnostic interface from unusual source IP addresses or during non-business hours. Baseline normal operator behavior and alert on deviations. Review access logs for correlation between specific operator sessions and controller restart events.

Why prioritize this

Despite its LOW CVSS score, this vulnerability warrants prompt attention in high-security or compliance-critical environments where access control continuity is non-negotiable. The requirement for high-privilege credentials limits urgency in organizations with strong credential management and role-based access control. However, insider threats or credential compromise scenarios elevate practical risk. Prioritize patching for: (1) facilities with single controllers or no failover; (2) organizations with relaxed access control governance; (3) systems supporting critical infrastructure or regulated industries. Others may schedule patches during regular maintenance windows.

Risk score, explained

The CVSS 3.1 score of 2.7 (LOW severity) reflects the attack complexity: authentication and high-privilege authorization are mandatory, network accessibility is present, and only availability is impacted. The score appropriately de-weights this against scenarios where attackers lack credentials. However, context matters: a malicious insider or an attacker with stolen high-privilege credentials poses material risk to access control availability. Security leaders should consider this a contextual rather than absolute risk assessment.

Frequently asked questions

Can an unauthenticated attacker exploit this?

No. The vulnerability requires valid operator credentials and high-level authorization within Command Centre. Unauthenticated requests to the diagnostic interface will be rejected.

Does this vulnerability allow data theft or unauthorized access to the building?

No. The flaw only triggers a temporary restart of the controller, disrupting access control functions until recovery. It does not bypass authentication, extract data, or elevate privileges.

What is the difference between the version numbers and the 'vCR' numbers mentioned?

The vCR prefix denotes the internal patch build identifier (e.g., vCR9.50.260616a). This patch is distributed within the published maintenance release (e.g., 9.50.1587 MR1). Verify your exact running version in Command Centre settings and cross-reference the advisory to confirm you are at or above the patched build.

If I can't patch immediately, what interim controls help?

Restrict network access to the diagnostic interface to trusted administrator workstations only via firewall or network segmentation. Audit and minimize the number of operators with high-privilege roles. Enable detailed logging of diagnostic interface access and monitor for anomalies. These measures reduce both the likelihood and impact of exploitation.

This analysis is provided for informational purposes and does not constitute security advice. Organizations must verify all information against official Gallagher security advisories, release notes, and their own environment configurations. Patch versions, affected software, and remediation guidance are based on vendor-supplied data; verify these details before deployment. Security risks are contextual; assess impact based on your specific architecture, access controls, and business requirements. Consult qualified security and IT personnel before implementing changes. Source: NVD (public-domain), retrieved 2026-08-15. Analysis generated by SEC.co (claude-haiku-4-5).