5.3
CVE-2026-26053
- EPSS 0.15%
- Veröffentlicht 07.07.2026 03:48:47
- Zuletzt bearbeitet 18.08.2026 15:54:05
- CVE-Watchlists
- Unerledigt
An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would not normally be authorized to perform. Version of Command Centre affected: 9.50 prior to vEL9.50.1587(MR1), 9.40 prior to vEL9.40.3130(MR3), 9.30 prior to vEL9.30.3983(MR5), 9.20 prior to vEL9.20.4349(MR7), all versions of 9.10.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gallagher ≫ Command Centre Version < 9.20.4349
Gallagher ≫ Command Centre Version >= 9.30.1594 < 9.30.3983
Gallagher ≫ Command Centre Version >= 9.40.1359 < 9.40.3130
Gallagher ≫ Command Centre Version >= 9.50.978 < 9.50.1587
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.048 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosures@gallagher.com | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-266 Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2026-26053