CVE-2026-78224: NextGen Healthcare Mirth Connect Improper Restriction of XML External Entity Reference
The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NextGen Healthcare Mirth Connectto a version that resolves this vulnerability.Fixed in 4.7.2
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is remotely exploitable without privileges or user interaction, as indicated by the network attack vector and PR:N/UI:N metrics. Exploitation requires reaching functionality that processes attacker-controlled XML through an XSLT Transformer Step.
What impact can successful exploitation have?
An attacker may use XML external entity injection to exfiltrate data or cause denial of service. The supplied severity vector rates confidentiality impact as high and availability impact as low, with no integrity impact indicated.