<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 20:16:12 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-25193</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-25193</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Gallagher Command Centre Server, Gallagher Active Directory Sync, Gallagher Cardholder Sync Utility, Gallagher Diagnostics Service, Gallagher Elevator Service, Gallagher Encoding Kiosk Application, Gallagher Entra ID Sync, Gallagher Event Sync Utility, Gallagher Event Logger, Gallagher Middleware Framework and 4 more&lt;/p&gt;
&lt;p&gt;Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. 
Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.&lt;/p&gt;
&lt;p&gt;Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Gallagher Command Centre Server, Gallagher Active Directory Sync, Gallagher Cardholder Sync Utility, Gallagher Diagnostics Service, Gallagher Elevator Service, Gallagher Encoding Kiosk Application, Gallagher Entra ID Sync, Gallagher Event Sync Utility, Gallagher Event Logger, Gallagher Middleware Framework and 4 more&lt;/p&gt;
&lt;p&gt;Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. 
Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.&lt;/p&gt;
&lt;p&gt;Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-25193</guid>
    </item>
  </channel>
</rss>
