NextGen Healthcare Mirth Connect

Plan PatchCVSS 8.3ICS-CERT ICSMA-26-253-01Sep 10, 2026
Healthcare
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Mirth Connect versions 4.7.1 and earlier contain SQL injection (CWE-89) and XML external entity (CWE-611) vulnerabilities that allow authenticated attackers to extract sensitive data from the database or trigger denial-of-service conditions affecting message routing and healthcare data exchange operations.

What this means
What could happen
An attacker with valid credentials could steal patient data or disrupt the message routing system, preventing healthcare facilities from exchanging critical patient information between systems.
Who's at risk
Healthcare facilities using Mirth Connect for electronic health information exchange should prioritize this update. The vulnerability affects message routing appliances and servers that connect disparate clinical systems and patient data repositories.
How it could be exploited
An attacker with valid login credentials accesses the Mirth Connect web interface remotely and exploits SQL injection or XML external entity vulnerabilities to extract data from the database or cause the service to become unresponsive.
Prerequisites
  • Valid user credentials for Mirth Connect web interface
  • Network access to Mirth Connect management port (typically port 8080 or 8443)
  • Authentication required
remotely exploitablerequires valid credentialslow attack complexityaffects patient data confidentiality and availability
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (1)
ProductAffected VersionsFix Status
Mirth Connect≤ v4.7.1Fix available
Remediation & Mitigation
0/3
Do now
0/2
WORKAROUNDRestrict network access to Mirth Connect management interface to authorized administrative networks only
HARDENINGEnforce strong, unique passwords for all Mirth Connect user accounts
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Mirth Connect to version 4.7.2 or later
API: /api/v1/advisories/d9fa7775-560c-452a-b8ca-624b08835e6c

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.