SQL Injection Vulnerability in NextGen Connect by NextGen Healthcare
CVE-2026-82583
7.2HIGH
What is CVE-2026-82583?
NextGen Connect (Mirth Connect) versions 4.7.1 and earlier are susceptible to a SQL injection vulnerability that allows authenticated users to execute arbitrary SQL commands via the Database Connector API. This could lead to unauthorized disclosure of sensitive stored credentials for connected systems, allow unexpected arbitrary file operations, and potentially cause a denial-of-service condition, compromising the integrity and availability of systems.
Affected Version(s)
Mirth Connect 0 <= 4.7.1
Mirth Connect 4.7.2
References
CVSS V4
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abhinav Agarwal reported this vulnerability to CISA.
