Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-11 ยท updated: 2026-09-11 ยท tags: [cve, nextgen, mirth-connect, sql-injection, healthcare, integration-engine] ยท confidence: high ยท severity: high ยท affected_sectors: [healthcare] ยท au_impact: false

CVE-2026-82583 is a high-severity SQL injection in NextGen Healthcare Mirth Connect, a cross-platform healthcare integration engine that connects, routes, transforms and exchanges clinical and administrative data between hospital systems. An authenticated user can execute arbitrary SQL through the Database Connector API, which could disclose database and configuration data and the stored credentials for connected systems, permit arbitrary file write, disrupt database-backed processing, or trigger denial of service. It carries a CVSS v3.1 score of 8.3 (v4.0: 7.2) and affected all versions up to and including v4.7.1; it is fixed in v4.7.2.

Attribute Detail
CVE CVE-2026-82583
CVSS 8.3 (v3.1) / 7.2 (v4.0)
Type SQL injection via Database Connector API
Affected Mirth Connect v4.7.1 and earlier
Fixed Mirth Connect v4.7.2
Reported by Abhinav Agarwal
Published 2026-09-10

The reporting researcher highlighted the supply-chain visibility problem specific to integration software: hospitals frequently cannot see the name Mirth on the product they bought, because integration engines are embedded, resold or managed inside another vendor's offering. SBOMs and exact version disclosure are therefore the only reliable way for an affected organisation to know whether the vulnerable component is present. See also CVE-2026-78224 and CVE-2026-82578, patched in the same release.