CVE-2026-20801

Basic Information

Severity MEDIUM
Base Score 5.6
CNA Gallagher
Published Date 2026-03-02 21:41:10 UTC
Last Modified 2026-03-02 21:41:10 UTC
CVE.org Link https://www.cve.org/CVERecord?id=CVE-2026-20801
NVD https://nvd.nist.gov/vuln/detail/CVE-2026-20801

Description

Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations allows unprivileged users with local network access to view live video streams. This issue affects all versions of Gallagher NxWitness VMS integration prior to 9.10.017 and Gallagher Hanwha VMS integration prior to 9.10.025.

Affected Products

Vendor Product
gallagher nxwitness vms and hanwha vms integrations