CVE-2026-20757
Last modified
CVE-2026-20757 is a low-severity vulnerability rated 2.5/10 on the CVSS scale. Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server. This issue affects Command Centre Server: 9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vEL9.20.3783 (MR6), 9.10 prior to vEL9.10.4647 (MR9), all versions of 9.00 and prior.. EPSS estimates a 0.07% chance of exploitation in the next 30 days.
Description
Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server. This issue affects Command Centre Server: 9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vEL9.20.3783 (MR6), 9.10 prior to vEL9.10.4647 (MR9), all versions of 9.00 and prior.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Gallagher | Command Centre Server | <= 9.00; >= 9.40, < 9.40.1976(MR1); >= 9.30, < 9.30.3382 (MR4); >= 9.20, < 9.20.3783 (MR6); >= 9.10, < 9.10.4647 (MR9) |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-20757?
How severe is CVE-2026-20757?
How do I fix CVE-2026-20757?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-20750Gitea does not properly validate project ownership in organi…9.1
- CVE-2026-20751Out-of-bounds read for the Intel(R) Data Center Graphics Dri…8.3
- CVE-2026-20752Improper authentication for some Intel(R) PROSet/Wireless Wi…6.7
- CVE-2026-20753Integer overflow in the UEFI firmware for the Slim Bootloade…8.7
- CVE-2026-20754Improper conditions check in some firmware for some Intel(R)…6.9
- CVE-2026-20755Protection mechanism failure for some LLM Scaler software wi…5.4
- CVE-2026-20759OS Command Injection vulnerability exists in multiple Networ…8.8
- CVE-2026-2076A weakness has been identified in yeqifu warehouse up to aaf…8.8
- CVE-2026-20760Improper handling of overlap between protected memory ranges…6.8
- CVE-2026-20761A vulnerability exists in EnOcean SmartServer IoT version 4.…8.1
- CVE-2026-20763Incorrect calculation for some Intel(R) TDX Guest software b…4.6
- CVE-2026-20764An OS command injection vulnerability exists in XWEB Pro ve…8.8
Are you affected by CVE-2026-20757?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
