type: cve ยท created: 2026-09-11 ยท updated: 2026-09-11 ยท tags: [cve, nextgen, mirth-connect, xxe, healthcare, integration-engine] ยท confidence: high ยท severity: high ยท affected_sectors: [healthcare] ยท au_impact: false
CVE-2026-82578 is an XML External Entity (XXE) injection flaw in NextGen Healthcare Mirth Connect that triggers when XML batch processing is enabled and the XPath option is selected: raw batch input passes through a default XPath/JAXP setup with no entity restrictions. Exploitation can expose server-local files and enable data exfiltration and denial-of-service attacks. It carries a CVSS v3.1 score of 7.5 (v4.0: 8.7), affected all versions up to and including v4.7.1, and is fixed in v4.7.2.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-82578 |
| CVSS | 7.5 (v3.1) / 8.7 (v4.0) |
| Type | XXE injection via XML batch processing / XPath |
| Affected | Mirth Connect v4.7.1 and earlier |
| Fixed | Mirth Connect v4.7.2 |
| Published | 2026-09-10 |
The three Mirth Connect flaws patched in v4.7.2 โ this one, CVE-2026-82583 and CVE-2026-78224 โ share a common root cause: security defaults omitted in library construction. See also CVE-2026-82583 and CVE-2026-78224.