When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
NextGen recommends users update Mirth Connect v4.7.2 or later. Users can download the latest version from the NextGen Healthcare customer portal.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks. | |
| Title | NextGen Healthcare Mirth Connect Improper Restriction of XML External Entity Reference | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-11T14:57:02.218Z
Reserved: 2026-09-03T21:01:37.563Z
Link: CVE-2026-82578
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses