CVE-2026-82583

8.3

NextGen Healthcare · Mirth Connect

NextGen Connect (Mirth Connect) versions 4.7.1 and earlier are vulnerable to SQL injection via the Database Connector API, allowing authenticated users to perform unauthorized data and system operations.

Executive summary

NextGen Mirth Connect versions 4.7.1 and earlier contain a critical SQL injection vulnerability that allows authenticated attackers to compromise backend database integrity and system availability.

Vulnerability

The application is susceptible to SQL injection (CWE-89) within its Database Connector API. This flaw allows an attacker with authenticated access to execute arbitrary SQL commands, potentially leading to credential theft, unauthorized file writes, and denial-of-service conditions.

Business impact

Successful exploitation of this vulnerability poses a severe risk to healthcare data integrity and operational continuity. Because the flaw allows for the disclosure of stored credentials and arbitrary file operations, an attacker could pivot to connected systems or disrupt critical integration workflows, leading to significant reputational damage and regulatory non-compliance. Given the CVSS score of 8.3, this issue is classified as high severity and requires immediate attention to prevent unauthorized access to sensitive medical data environments.

Remediation

Immediate Action: Upgrade all instances of Mirth Connect to version 4.7.2 or later, which is available via the NextGen Healthcare customer portal.

Proactive Monitoring: Review database and application access logs for unusual query patterns, particularly those originating from the Database Connector API that deviate from standard operational traffic.

Compensating Controls: Implement strict network segmentation and apply the principle of least privilege to user accounts to limit the potential impact of an authenticated attacker.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The presence of a high-severity SQL injection vulnerability in a critical integration tool like Mirth Connect necessitates an urgent update. Organizations should prioritize patching to version 4.7.2 during the next maintenance window to eliminate the risk of database-level compromise. Failure to address this flaw leaves the environment exposed to potential data exfiltration and service disruption.

More NextGen Healthcare CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Abhinav Agarwal reported this vulnerability to CISA., per the CVE Program record.