Security Advisory for Mirth Connect: Three High-Severity Vulnerabilities Fixed by NextGen Healthcare
NextGen Healthcare has recently published a security advisory affecting certain versions of Mirth Connect, one of the most widely used interoperability platforms in healthcare for integrating clinical, administrative, and departmental systems.
According to the vendor, three high-severity vulnerabilities have been identified in Mirth Connect versions 4.7.1 and earlier. These issues have been addressed and remediated in version 4.7.2.
What Vulnerabilities Have Been Identified?
The advisory describes three separate vulnerabilities:
1. SQL Injection Vulnerability in the JDBC Connector
The vulnerability, tracked as CVE-2026-82583, affects the Mirth Connect JDBC connector. An authenticated user with access to the REST API could potentially execute unauthorized SQL operations, compromising the integrity of stored information and potentially impacting service availability.
This vulnerability has been assigned a CVSS score of 7.2/10.
2. XXE Vulnerability in XSLT Transformations
The second vulnerability, CVE-2026-78224, is related to the processing of XML documents through XSLT transformations. Under certain configurations, it could allow access to local files on the server or interfere with the processing of integration channels.
Its severity has been rated with a CVSS score of 8.8/10.
3. XXE Vulnerability in the XML Batch Adapter
The third vulnerability, CVE-2026-82578, affects environments that use the XML Batch Processing functionality. Under specific circumstances, it could enable unauthorized access to files hosted on the server running the platform.
This vulnerability has received a CVSS score of 8.7/10.
What Is the Potential Impact on Healthcare Organizations?
Interoperability platforms often play a critical role within healthcare technology ecosystems, connecting HIS, LIS, RIS, PACS, laboratory applications, appointment scheduling systems, patient portals, and numerous other components.
Although successful exploitation of these vulnerabilities depends on specific access conditions and configuration settings, any vulnerability affecting a central integration platform should be treated as a priority by IT and cybersecurity teams.
Vendor Recommendation
NextGen Healthcare states that these issues have been resolved in Mirth Connect 4.7.2 and recommends planning an upgrade to this version or any later release containing the necessary fixes.
For organizations that cannot upgrade immediately, the vendor recommends several temporary mitigation measures:
- Restrict access to the administrative API to trusted networks only.
- Review channels that perform XSLT transformations on externally received XML documents.
- Disable XML Batch Processing when it is not required.
Best Practices for Interoperability Administrators
Beyond this specific advisory, the situation highlights the importance of maintaining a continuous vulnerability management strategy for integration platforms:
- Keep the platform and all related components up to date.
- Regularly review connectors and transformation processes.
- Restrict administrative access according to the principle of least privilege.
- Segment the networks hosting integration engines.
- Incorporate interoperability workflows into corporate change management and cybersecurity processes.
Conclusion
The disclosure of these vulnerabilities reinforces the importance of keeping healthcare interoperability platforms fully updated.
Organizations running Mirth Connect 4.7.1 or earlier should review their current deployment, plan the vendor-recommended upgrade, and consider implementing the available mitigation measures until the update process has been completed.