Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-11 ยท updated: 2026-09-11 ยท tags: [cve, nextgen, mirth-connect, xxe, healthcare, integration-engine] ยท confidence: high ยท severity: high ยท affected_sectors: [healthcare] ยท au_impact: false

CVE-2026-82578 is an XML External Entity (XXE) injection flaw in NextGen Healthcare Mirth Connect that triggers when XML batch processing is enabled and the XPath option is selected: raw batch input passes through a default XPath/JAXP setup with no entity restrictions. Exploitation can expose server-local files and enable data exfiltration and denial-of-service attacks. It carries a CVSS v3.1 score of 7.5 (v4.0: 8.7), affected all versions up to and including v4.7.1, and is fixed in v4.7.2.

Attribute Detail
CVE CVE-2026-82578
CVSS 7.5 (v3.1) / 8.7 (v4.0)
Type XXE injection via XML batch processing / XPath
Affected Mirth Connect v4.7.1 and earlier
Fixed Mirth Connect v4.7.2
Published 2026-09-10

The three Mirth Connect flaws patched in v4.7.2 โ€” this one, CVE-2026-82583 and CVE-2026-78224 โ€” share a common root cause: security defaults omitted in library construction. See also CVE-2026-82583 and CVE-2026-78224.