CVE-2025-35981

Severity: Medium CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Components affected: Command Centre Server

Version of Command Centre affected: vEL9.30.1874 (MR1), vEL9.20.2337 (MR3), vEL9.10.3194 (MR6). No other versions of Command Centre are affected. 

Reported by: Gallagher Internal

Active exploitation of vulnerability*: No

Description of vulnerability: Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privileged Operator to view limited personal data about a Cardholder they would not normally have permissions to view.

*This indicates whether Gallagher are aware of this being actively exploited against customer sites at the time of publication.

Stay up to date with Gallagher

Get the latest Gallagher news, updates, and event information delivered straight to your inbox.