Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
NextGen recommends users update Mirth Connect v4.7.2 or later. Users can download the latest version from the NextGen Healthcare customer portal.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 11 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks. | |
| Title | NextGen Healthcare Mirth Connect Improper Restriction of XML External Entity Reference | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-11T14:57:02.383Z
Reserved: 2026-09-03T21:01:37.559Z
Link: CVE-2026-78224
Updated: 2026-09-11T14:55:13.129Z
Status : Received
Published: 2026-09-11T15:17:04.337
Modified: 2026-09-11T15:17:04.337
Link: CVE-2026-78224
No data.
OpenCVE Enrichment
Updated: 2026-09-11T16:00:06Z