type: cve ยท created: 2026-09-11 ยท updated: 2026-09-11 ยท tags: [cve, nextgen, mirth-connect, xxe, healthcare, integration-engine] ยท confidence: high ยท severity: high ยท affected_sectors: [healthcare] ยท au_impact: false
CVE-2026-78224 is an XML External Entity (XXE) injection flaw in NextGen Healthcare Mirth Connect, arising because the XSLT Transformer Step builds a bare TransformerFactory without the required security options set. An unauthenticated sender can read server-local files and stall an affected channel, giving both data exfiltration and denial-of-service outcomes. It carries a CVSS v3.1 score of 8.2 (v4.0: 8.8), affected all versions up to and including v4.7.1, and is fixed in v4.7.2.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-78224 |
| CVSS | 8.2 (v3.1) / 8.8 (v4.0) |
| Type | XXE injection via XSLT Transformer Step |
| Affected | Mirth Connect v4.7.1 and earlier |
| Fixed | Mirth Connect v4.7.2 |
| Published | 2026-09-10 |
Mirth Connect sits as a switchboard between laboratory systems, imaging systems, databases and clinical applications, so a flaw in the integration layer can expose far more than a single application. See also CVE-2026-82583 and CVE-2026-82578.