ZeroHour
Product

Mirth Connect

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

CVE-2026-82583, CVE-2026-78224, CVE-2026-82578: NextGen Mirth Connect SQL injection and XXE

CISA advisory ICSMA-26-253-01 covers three NextGen Mirth Connect flaws, including SQL injection and XXE, with testing performed against version 4.5.2.

CISA has published ICS Medical Advisory ICSMA-26-253-01 covering three vulnerabilities in NextGen Mirth Connect, the open-source healthcare integration engine. The flaws include SQL injection and XML external entity (XXE) injection, tracked as CVE-2026-82583, CVE-2026-78224 and CVE-2026-82578, with testing performed against version 4.5.2. The findings were announced on the oss-security mailing list by researcher Abhinav Agarwal on September 11.

NextGen Healthcare Mirth Connect

CISA warns NextGen Healthcare Mirth Connect <=4.7.1 has SQL injection and XXE flaws enabling credential theft, file writes, and DoS.

CISA released advisory ICSMA-26-253-01 covering three vulnerabilities in NextGen Healthcare Mirth Connect versions 4.7.1 and earlier: SQL injection CVE-2026-82583 (CVSS 8.3), XXE CVE-2026-78224 (CVSS 8.2), and XXE CVE-2026-82578 (CVSS 7.5). Exploitation could expose stored credentials for connected systems, enable arbitrary file writes, and cause denial-of-service conditions. No public exploitation has been reported; the product is deployed worldwide in the Healthcare and Public Health sector.

CISA Advisoriesupdated · 4d agofirst · 5d agoAdvisory 2 sourcesCVE-2026-82583CVE-2026-78224CVE-2026-82578

Related CVEs

  • XXE Injection in NextGen Healthcare Mirth Connect XSLT Transformer Step
    CVE-2026-78224 is an XML External Entity (XXE) injection flaw (CWE-611) in the XSLT Transformer step of NextGen Healthcare's Mirth Connect integration engine, where the step builds a bare TransformerFactory without the security options that restrict external entities and DTDs. It is triggered when a channel's XSLT Transformer step parses attacker-influenced XML; the CVSS 4.0 vector (AV:N/PR:N/UI:N) indicates a remote, unauthenticated attacker with no user interaction can reach the vulnerable processing. Successful exploitation yields a high confidentiality impact (local file disclosure and data exfiltration via external entity resolution) plus a limited availability impact from denial-of-service, with no scored integrity impact. Only Mirth Connect deployments whose channels use the XSLT Transformer step with attacker-reachable input are exploitable, and the available data does not specify affected or fixed version numbers. The issue was assigned by CISA ICS-CERT and disclosed alongside CVE-2026-82583 (SQL injection) and CVE-2026-82578 in NextGen Mirth Connect; it is not in CISA KEV and no public proof-of-concept is known.
    · NextGen Healthcare Mirth Connectlarge
  • Unauthenticated XXE in NextGen Mirth Connect XML Batch Processing
    CVE-2026-82578 is an XML External Entity (XXE) injection flaw (CWE-611) in NextGen Healthcare's Mirth Connect integration engine: when a channel has XML batch processing enabled and the XPath option selected, raw batch input is parsed through a default XPath/JAXP configuration with no restrictions on external entities. An unauthenticated network attacker who can submit data to such a channel can supply crafted XML with external entity references, causing the parser to read local files or internal resources and disclose them, or to consume resources and cause denial of service. The CVSS 4.0 score of 8.7 (High) reflects a network-adjacent, unauthenticated attack with high confidentiality impact; given Mirth Connect's role as a healthcare integration engine, exfiltrated data may include patient or clinical messages passing through affected channels. Organizations running Mirth Connect with XML batch processing plus the XPath option are affected; those using other batch or message processing modes are not. No public proof-of-concept, no CISA KEV listing, and no known in-the-wild exploitation have been reported as of this analysis.
    · NextGen Healthcare Mirth Connectmoderate
  • Authenticated SQL Injection in NextGen Connect (Mirth Connect) 4.7.1 and Earlier
    NextGen Connect (Mirth Connect) versions 4.7.1 and earlier contain a SQL injection flaw (CWE-89) in the Database Connector API. An attacker needs valid credentials but no elevated privileges or user interaction: an authenticated user can send crafted input to the connector API to execute arbitrary SQL against the underlying database. Successful exploitation can disclose credentials stored in Mirth Connect for connected downstream systems, write arbitrary files on the host (which could enable further compromise), and cause a denial-of-service condition. Any organization running NextGen Connect 4.7.1 or earlier — most commonly hospitals and health systems using it as an HL7/healthcare integration engine — is affected. As of now the flaw is not in the CISA KEV, no public proof-of-concept is known, and there are no reports of in-the-wild exploitation.
    · NextGen Healthcare NextGen Connect (Mirth Connect) 4.7.1 and earliermoderate

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.