CVE-2026-20757
Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server. This issue affects Command Centre Server: 9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vEL9.20.3783 (MR6), 9.10 prior to vEL9.10.4647 (MR9), all versions of 9.00 and prior.
Scoring
- Severity
- LOW
- CVSS base score
- 2.5
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.07%
- CWE
- CWE-667
- Published
- 2026-03-03
- Last modified
- 2026-03-12
Affected products
- Gallagher Command Centre Server
- Gallagher Command Centre Server
- Gallagher Command Centre Server
- Gallagher Command Centre Server
- Gallagher Command Centre Server
Weakness type
Related vulnerabilities
- CVE-2026-80126 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-45404 — OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access
- CVE-2026-54906 — concurrent-ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption
- CVE-2026-24182 — NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak...
- CVE-2026-20065 — Multiple Cisco Products Snort 3 TBD Denial of Service Vulnerability
- CVE-2026-21914 — Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crash
- CVE-2025-68657 — espressif/usb_host_hid Double-Free Race Condition in USB Host HID Device Close Path
- CVE-2025-34467 — ZwiiCMS < 13.7.00 Lock Persistence Authenticated DoS Against Administrative Pages