Skip to content
Threat Feed
high advisory

Critical Vulnerabilities in NextGen Healthcare Mirth Connect

NextGen Healthcare Mirth Connect versions 4.7.1 and earlier contain three critical vulnerabilities including SQL injection and XML External Entity (XXE) injection flaws that allow for unauthorized data access and denial-of-service.

NextGen Healthcare Mirth Connect versions 4.7.1 and earlier are affected by multiple high-severity vulnerabilities. These flaws include CVE-2026-82583, a SQL injection vulnerability within the Database Connector API that allows authenticated users to execute arbitrary SQL commands, potentially leading to credential disclosure, arbitrary file writes, and denial-of-service. Additionally, CVE-2026-78224 and CVE-2026-82578 involve improper restriction of XML External Entity (XXE) references within the XSLT Transformer step and XML batch processing, respectively. These XXE vulnerabilities enable unauthenticated attackers to perform data exfiltration and cause denial-of-service conditions. Mirth Connect is widely used in the healthcare sector for clinical data integration, making these flaws a significant target for actors seeking unauthorized access to sensitive medical data.

Impact

Successful exploitation of these vulnerabilities can result in severe consequences, including the compromise of stored credentials for integrated systems, unauthorized access to sensitive patient data, arbitrary file system manipulation, and persistent denial-of-service of the Mirth Connect interface. These vulnerabilities affect healthcare organizations worldwide, potentially disrupting critical clinical workflows.

Recommendation

  • Immediately upgrade NextGen Healthcare Mirth Connect to version 4.7.2 or later as recommended by the vendor.
  • Minimize network exposure by ensuring Mirth Connect instances are not directly accessible from the internet and are located behind firewalls.
  • Implement defense-in-depth strategies to isolate clinical systems from general business networks.
  • Monitor web server logs and database access logs for anomalous SQL queries or attempts to inject external entities into XML processing streams.

Immediate actions

Upgrade all Mirth Connect instances to version 4.7.2 or later.

IT Operations 24h

Mitigations

Isolate Mirth Connect instances from internet access via firewall rules.

immediate Network Security

CVE-2026-78224, CVE-2026-82578