CVE-2026-20801
Summary
| CVE | CVE-2026-20801 |
|---|---|
| State | PUBLISHED |
| Assigner | Gallagher |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-03-03 03:15:54 UTC |
| Updated | 2026-08-17 19:03:02 UTC |
| Description | Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations allows unprivileged users with local network access to view live video streams. This issue affects all versions of Gallagher NxWitness VMS integration prior to 9.10.017 and Gallagher Hanwha VMS integration prior to 9.10.025. |
Risk And Classification
Primary CVSS: v3.1 5.6 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS: 0.001020000 probability, percentile 0.010660000 (date 2026-08-18)
Problem Types: CWE-319 | CWE-319 CWE-319 Cleartext Transmission of Sensitive Information
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.6 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L |
| 3.1 | CNA | CVSS | 5.6 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
LowCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gallagher | Hanwha Vms Integration | All | All | All | All |
| Application | Gallagher | Nx Witness Vms Integration | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Gallagher | NxWitness VMS And Hanwha VMS Integrations | affected 9.10.017 custom | Not specified |
| CNA | Gallagher | NxWitness VMS And Hanwha VMS Integrations | affected 9.10.025 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security.gallagher.com/en-NZ/Security-Advisories/CVE-2026-20801 | [email protected] | security.gallagher.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.