Description
An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would not normally be authorized to perform. Version of Command Centre affected: 9.50 prior to vEL9.50.1587(MR1), 9.40 prior to vEL9.40.3130(MR3), 9.30 prior to vEL9.30.3983(MR5), 9.20 prior to vEL9.20.4349(MR7), all versions of 9.10.
Published: 2026-07-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Incorrect Privilege Assignment flaw implemented in the Gallagher Command Centre Server allows an authenticated operator with limited privilege to carry out operations they should not be permitted to perform. The weakness, classified as CWE-266, directly impacts the integrity of the system by enabling the elevation of privileges within the server’s operational scope.

Affected Systems

Gallagher Command Centre Server versions 9.50 prior to vEL9.50.1587(MR1), 9.40 prior to vEL9.40.3130(MR3), 9.30 prior to vEL9.30.3983(MR5), 9.20 prior to vEL9.20.4349(MR7), and all 9.10 releases are affected. Patched releases are available starting with the specified milestones for each major version.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a legitimate authenticated user with limited privileges; from that position an attacker can perform privileged actions beyond their authorized scope within the server’s environment.

Generated by OpenCVE AI on August 3, 2026 at 04:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest patched release for your Gallagher Command Centre Server version, such as vEL9.50.1587(MR1) or newer, vEL9.40.3130(MR3) or newer, vEL9.30.3983(MR5) or newer, vEL9.20.4349(MR7) or newer, or the most recent 9.10 release.
  • After upgrading, audit user accounts to confirm that operators with limited privileges remain appropriately restricted and remove any excessive rights.
  • Enable and monitor logs for privileged actions to detect any unauthorized activity.

Generated by OpenCVE AI on August 3, 2026 at 04:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Incorrect Privilege Assignment in Gallagher Command Centre Server

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Incorrect Privilege Assignment in Gallagher Command Centre Server Enables Limited‑Privilege Operators to Escalate Permissions

Thu, 23 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Incorrect Privilege Assignment in Gallagher Command Centre Server Enables Limited‑Privilege Operators to Escalate Permissions

Tue, 21 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Authenticated Operators Can Escalate Privileges in Gallagher Command Centre Server

Wed, 15 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Authenticated Operators Can Escalate Privileges in Gallagher Command Centre Server

Mon, 13 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Incorrect Privilege Assignment in Gallagher Command Centre Server

Sun, 12 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Incorrect Privilege Assignment in Gallagher Command Centre Server

Fri, 10 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Incorrect Privilege Assignment in Gallagher Command Centre Server

Fri, 10 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Incorrect Privilege Assignment in Gallagher Command Centre Server

Thu, 09 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Incorrect Privilege Assignment in Gallagher Command Centre Server

Wed, 08 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Incorrect Privilege Assignment in Gallagher Command Centre Server

Wed, 08 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Authenticated Operator Privilege Escalation in Gallagher Command Centre Server

Tue, 07 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Authenticated Operator Privilege Escalation in Gallagher Command Centre Server

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Description An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would not normally be authorized to perform. Version of Command Centre affected: 9.50 prior to vEL9.50.1587(MR1), 9.40 prior to vEL9.40.3130(MR3), 9.30 prior to vEL9.30.3983(MR5), 9.20 prior to vEL9.20.4349(MR7), all versions of 9.10.
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Gallagher

Published:

Updated: 2026-07-07T13:37:52.035Z

Reserved: 2026-03-01T23:45:09.665Z

Link: CVE-2026-26053

cve-icon Vulnrichment

Updated: 2026-07-07T13:37:47.694Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-07T05:16:50.117

Modified: 2026-07-07T14:16:29.567

Link: CVE-2026-26053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T05:00:16Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment