Gallagher Command Centre Server Improper Locking Vulnerability Leading to Denial-of-Service

Vulnerability

A denial-of-service vulnerability has been identified in Gallagher Command Centre Server versions 9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vEL9.20.3783 (MR6), 9.10 prior to vEL9.10.4647 (MR9), and all versions of 9.00 and prior. This vulnerability arises from improper locking in the Gallagher Morpho integration, allowing a privileged operator to cause a limited denial-of-service on the Command Centre Server.

Impact

Exploitation of this vulnerability leads to a limited denial-of-service on the Command Centre Server, causing disruption without crashing the server.

Added: Mar 3, 2026, 3:18 AM
Updated: Mar 3, 2026, 3:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
0.6
exploitability
2.6
remediation
7.7
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.