---
id: CVE-2026-20757
title: "Improper Locking\_vulnerability (CWE-667) in\_Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server.\n\n\n\nThis issue affects Command Centre Server: \n\n9.40 prior to vEL9.40…"
summary: "Improper Locking\_vulnerability (CWE-667) in\_Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server.\n\n\n\nThis issue affects Command Centre Server: \n\n9.40 prior to vEL9.40…"
severity: low
cvss: 2.5
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-667
vendor: gallagher
product: command_centre
affected:
  - command_centre < 9.10.4647
  - 'command_centre >= 9.20.1043, < 9.20.3783'
  - 'command_centre >= 9.30.1594, < 9.30.3382'
  - 'command_centre >= 9.40.1359, < 9.40.1976'
patched:
  - command_centre 9.40.1976
published: '2026-03-03'
updated: '2026-08-18'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20757'
references:
  - url: 'https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2026-20757'
    label: disclosures@gallagher.com
tags:
  - nvd
epss: 0.00069
epssPercentile: 0.00027
ingestedAt: '2026-08-18T16:19:51.788Z'
---

## Overview

Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server.



This issue affects Command Centre Server: 

9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vEL9.20.3783 (MR6), 9.10 prior to vEL9.10.4647 (MR9), all versions of 9.00 and prior.

## Affected

- `command_centre < 9.10.4647`
- `command_centre >= 9.20.1043, < 9.20.3783`
- `command_centre >= 9.30.1594, < 9.30.3382`
- `command_centre >= 9.40.1359, < 9.40.1976`

## Remediation

Upgrade past the affected range:

- `command_centre 9.40.1976`
