CVE-2026-78224
8.2NextGen Healthcare · Mirth Connect
NextGen Mirth Connect contains an XML External Entity (XXE) injection vulnerability in the XSLT Transformer Step, potentially allowing data exfiltration and denial of service.
Executive summary
The NextGen Mirth Connect XSLT Transformer Step is vulnerable to unauthenticated XXE injection, posing a significant risk of data exfiltration and service disruption.
Vulnerability
This vulnerability occurs because the XSLT Transformer Step initializes a TransformerFactory without implementing required security configurations to disable external entity processing. An unauthenticated attacker can leverage this flaw to perform unauthorized data exfiltration or trigger denial of service conditions.
Business impact
The ability to perform XXE injection allows attackers to read sensitive files from the underlying server or interact with internal network resources, leading to potential data breaches of PHI or other proprietary information. With a CVSS score of 8.2, this vulnerability represents a high-risk security gap that could lead to full system compromise or significant operational downtime for healthcare integration environments.
Remediation
Immediate Action: Update Mirth Connect to version 4.7.2 or later, which is available via the NextGen Healthcare customer portal.
Proactive Monitoring: Monitor application and system logs for unexpected outbound network requests or attempts to access system-level files from the Mirth Connect service account.
Compensating Controls: Deploy a Web Application Firewall (WAF) configured to block XML payloads containing DOCTYPE declarations or external entity references as a temporary protective measure.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the nature of Mirth Connect as a critical integration hub in medical environments, this vulnerability requires immediate attention. Organizations must prioritize the transition to version 4.7.2 to eliminate the underlying XXE weakness and prevent potential unauthorized access to sensitive healthcare data.
More NextGen Healthcare CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Abhinav Agarwal reported this vulnerability to CISA., per the CVE Program record.