AI analysis
CVE-2026-78224 is an XML External Entity (XXE) injection flaw (CWE-611) in the XSLT Transformer step of NextGen Healthcare's Mirth Connect integration engine, where the step builds a bare TransformerFactory without the security options that restrict external entities and DTDs. It is triggered when a channel's XSLT Transformer step parses attacker-influenced XML; the CVSS 4.0 vector (AV:N/PR:N/UI:N) indicates a remote, unauthenticated attacker with no user interaction can reach the vulnerable processing. Successful exploitation yields a high confidentiality impact (local file disclosure and data exfiltration via external entity resolution) plus a limited availability impact from denial-of-service, with no scored integrity impact. Only Mirth Connect deployments whose channels use the XSLT Transformer step with attacker-reachable input are exploitable, and the available data does not specify affected or fixed version numbers. The issue was assigned by CISA ICS-CERT and disclosed alongside CVE-2026-82583 (SQL injection) and CVE-2026-82578 in NextGen Mirth Connect; it is not in CISA KEV and no public proof-of-concept is known.
What to do: Apply the NextGen Healthcare Mirth Connect patch announced for this advisory once identified (no fixed version is given in the available data), prioritizing instances whose Mirth Connect listener ports are internet-exposed and channels that use the XSLT Transformer step. As interim mitigation, restrict network access to Mirth Connect interfaces and ensure XML parsing in the XSLT Transformer step disables external entities and DTDs. Also review your environment for the companion issues CVE-2026-82583 (SQL injection) and CVE-2026-82578 when planning the same update window.
Affected
| NextGen Healthcare Mirth Connect | — |
Estimated exposure
largetens of thousands of deployments, with only a few thousand internet-exposed instances per public scans — Mirth Connect is a widely adopted open-source healthcare/HL7 integration engine used across thousands of healthcare organizations, and historical public internet scans of its exposed admin/API listener interfaces typically show low…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.