CVE-2026-41939: Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly

Published Jul 29, 2026
·
Updated

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Archive file through the Deployments interface to achieve remote code execution as the Windows machine account. Version 14.x.x was declared end-of-life (EOL) in 2017 and future releases have addressed the vulnerable finding.

Affected Software

2 affected components
Allscripts Care Everywhere Gateway=14.3.10
Red Hat WildFly 8.2.0.Final=8.2.0.Final

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Care Everywhere Gateway to a version that resolves this vulnerability.

    Fixed in 14.3.10
  2. Upgrade

    Upgrade WildFly management interface bundled in Care Everywhere Gateway to a version that resolves this vulnerability.

    Fixed in 8.2.0.Final
  3. Compensating control

    Restrict network access to the WildFly management console on port 20990 so only trusted/admin hosts can reach it; block all other inbound access via firewall/ACL.

  4. Compensating control

    If you cannot immediately upgrade, prevent unauthenticated use of the WildFly Deployments interface by blocking access to the management interface endpoints used for deployments (port 20990) from untrusted networks.

Event History

Jul 29, 2026
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-41939?

CVE-2026-41939 has a critical severity score of 9.8.

2

How do I fix CVE-2026-41939?

To mitigate CVE-2026-41939, it is essential to change the hard-coded credentials immediately and ensure that proper authentication measures are implemented.

3

What systems are affected by CVE-2026-41939?

CVE-2026-41939 affects Allscripts Care Everywhere Gateway version 14.3.10 and Red Hat WildFly 8.2.0.Final.

4

What kind of attack can exploit CVE-2026-41939?

CVE-2026-41939 can be exploited by unauthenticated remote attackers gaining administrative access through default credentials.

5

Is there a known workaround for CVE-2026-41939?

Currently, the recommended workaround for CVE-2026-41939 is to remove or disable the management interface if not in use and to implement firewall rules to restrict access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203