5.3

CVE-2026-26053

An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would not normally be authorized to perform. Version of Command Centre affected: 9.50 prior to vEL9.50.1587(MR1), 9.40 prior to vEL9.40.3130(MR3), 9.30 prior to vEL9.30.3983(MR5), 9.20 prior to vEL9.20.4349(MR7), all versions of 9.10.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GallagherCommand Centre Version < 9.20.4349
GallagherCommand Centre Version >= 9.30.1594 < 9.30.3983
GallagherCommand Centre Version >= 9.40.1359 < 9.40.3130
GallagherCommand Centre Version >= 9.50.978 < 9.50.1587
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.048
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
disclosures@gallagher.com 5.3 1.6 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
CWE-266 Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2026-26053
Vendor Advisory