Where
-Infinity
0

Vendor Risk Score

See how nextgen healthcare compares to other vendors in security performance

View Risk Score →
Severity
9.8
EPSS
0.35%
OS Command Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.

1 / 2
Source: MITRE
First published (updated )
Severity
8.8
XEE
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.

First published (updated )
Severity
8.7
XEE
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.

First published (updated )
Severity
7.2
SQL Injection
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H

NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and a denial-of-service condition.

First published (updated )

CISA has published ICSMA-26-253-01 for three vulnerabilities in NextGen Mirth Connect, a healthcare integration engine. Mirth Connect 4.7.1 and earlier are affected; 4.7.2 or later fixes all three.

Mirth Connect was open source through 4.5.2; releases since 4.6 are closed source. The former public source and release history remain at https://github.com/nextgenhealthcare/connect, and all testing here was against 4.5.2.

Findings --------

1. CVE-2026-82583 - authenticated SQL injection in POST /api/connectors/jdbc/getTables. The selectLimit parameter is executed as arbitrary SQL. Against the bundled Derby database this exports live database content - administrator password hashes, and channel configuration containing plaintext connector credentials - to a web path retrievable without authentication. It can also freeze database-backed operations until the server is restarted. CVSS v3.1: 8.3 High (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H)

2. CVE-2026-78224 - unauthenticated XXE in the XSLT Transformer Step. Where a reachable channel runs inbound XML through an affected XSLT step, a crafted message exfiltrates a server-local file through an attacker-controlled callback. A slow external entity also blocks that channel; the control channel and administrative API stayed available in testing. CVSS v3.1: 8.2 High (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L)

3. CVE-2026-82578 - unauthenticated XXE in the XML Batch Adaptor. Where XML batch processing is enabled with an XPath-backed split mode, a crafted batch body exfiltrates a server-local file through an attacker-controlled callback, including when the listener returns HTTP 500. CVSS v3.1: 7.5 High (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Proof of concept ----------------

Full end-to-end exploits for all three findings are available at: https://github.com/abhinavagarwal07/mirth-connect-security-poc

Each harness launches the official 4.5.2 container image, attacks it from a separate container, and fails unless the claimed disclosure or availability effect is observed.

Coordination timeline ---------------------

2026-07-10 Reported all three findings to NextGen, set a 45-day disclosure date of August 24, and offered PoCs and logs privately. 2026-07-12 NextGen acknowledged the report; finding 2 was already fixed in 4.7.1, and findings 1 and 3 were scheduled for fixes. 2026-08-05 NextGen confirmed findings 1 and 3 fixed in 4.7.2 and finding 2 fixed in 4.7.1. 2026-08-14 CISA received the report and opened VU#656351. 2026-08-17 to 2026-08-18 NextGen requested September 24; I extended disclosure to September 7 for CVE assignment and validation, which NextGen accepted before moving coordination to CISA. 2026-09-10 CISA published ICSMA-26-253-01; the full PoCs and technical write-up were published.

References ----------

https://abhinavagarwal07.github.io/posts/nextgen-mirth-connect-sqli-xxe/?src=oss https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01

Findings 1 and 3 were reported by Abhinav Agarwal. Finding 2 was independently discovered by Abhinav Agarwal and first reported to NextGen by Youngdu.

-- Abhinav Agarwal

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203