High Severity Vulnerabilities Identified in NextGen Healthcare Mirth Connect
Three high-severity vulnerabilities have been identified in NextGen Healthcare Mirth Connect (Mirth Connect), a cross-platform healthcare integration engine for connecting, routing, transforming, and exchanging clinical and administrative data between different healthcare systems. The vulnerabilities are due to improper neutralization of special elements used in SQL commands and improper restriction of XML External Entity Reference. Successful exploitation of the vulnerabilities could allow denial-of-service attacks and data exfiltration.
The vulnerabilities were identified by security researcher Abhinav Agarwal. “Mirth Connect is effectively a switchboard between healthcare systems. It can sit between lab systems, imaging systems, databases, and clinical applications, so a vulnerability in the integration layer can expose much more than one isolated application,” Agarwal told The HIPAA Journal. A potential problem is that healthcare organizations may not know that they have a vulnerable component in one of their products. “A hospital may not see the name Mirth anywhere on the product it bought. Integration software can be managed, resold, or embedded inside another product, which is why SBOMs and exact version disclosure matter after vulnerabilities like these,” explained Agarwal.
- CVE-2026-82583 could be exploited by an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in the disclosure of database/configuration data and stored credentials for connected systems, allow arbitrary file write, disrupt database-backed processing, and trigger a denial-of-service condition. The vulnerability has been assigned a CVSS v3.1 severity score of 8.3 (v4:0: 7.2)
- CVE-2026-78224 is due to the XSLT Transformer Step building a bare TransformerFactory without the proper security options set. The vulnerability could allow an unauthenticated sender to read server-local files and stall an affected channel. Successful exploitation could result in data exfiltration and denial-of-service attacks via XXE injection. The vulnerability has a CVSS v3.1 severity score of 8.2 (v4.0: 8.8)
- CVE-2026-82578 can expose server-local files and allow data exfiltration and denial-of-service attacks via XXE injection. When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions. The vulnerability has a CVSS v3.1 severity score of 7.5 (v4.0: 8.7)
All three vulnerabilities affect v4.7.1 and earlier versions. NextGen has fixed all three vulnerabilities in Mirth Connect v4.7.2. Customers have been advised to update to the latest fixed version as soon as possible. The latest version can be downloaded from the NextGen Healthcare customer portal.

