Three flaws in Mirth Connect put clinical data routing at risk

Flaws in the middleware hospitals use to move lab, imaging and clinical data could hand attackers credentials and server files.

MedRisk Staff
By
2 Min Read

Three high-severity flaws have surfaced in NextGen Healthcare Mirth Connect, the integration engine many hospitals run quietly between laboratory, imaging and clinical systems.

Researcher Abhinav Agarwal found the bugs and described Mirth Connect as a switchboard between healthcare systems, warning that a flaw in the integration layer can expose far more than a single application. Many hospitals would not recognize the product name because the software is embedded, resold or managed on their behalf.

The first, CVE-2026-82583 (CVSS 8.3), lets an authenticated user run arbitrary SQL through a Database Connector API, exposing configuration data and stored credentials for connected systems, enabling file writes and triggering denial-of-service. CVE-2026-78224 (CVSS 8.2) stems from an XSLT Transformer Step built without hardened factory settings, and CVE-2026-82578 exposes server-local files through XPath batch processing. Both let unauthenticated senders read server files and stall channels through XXE injection.

For healthcare security teams the risk is lateral. Integration engines hold credentials to downstream systems, so one exposed interface can become a path to lab results, imaging archives and clinical records.

Agarwal urged hospitals to demand software bills of materials and exact version disclosure from vendors, since Mirth Connect may sit unnoticed inside a purchased product. Teams should inventory every instance, confirm whether a managed service runs it, and apply the fixes or restrict network access to the interface until patching is done.

Share This Article