Junglewise Threat Intelligence

CVE-2026-41939: Care Everywhere Gateway hard-coded credentials in WildFly interface

CVE-2026-41939 · Severity: critical · CVSS 9.8 · Published 2026-07-29

Executive brief

Care Everywhere Gateway is a server used to connect hospital systems and infusion pumps to electronic medical record (EMR) platforms. A vulnerability in the bundled WildFly management interface allows unauthorized individuals to log in using default, hard-coded credentials that are the same across all installations. An attacker can use this access to take full control of the server, potentially disrupting medical device connectivity or accessing sensitive patient data.

Technical details

The Care Everywhere Gateway (specifically version 14.3.10) bundles WildFly 8.2.0.Final, which exposes its management console on port 20990 by default. The system uses a hard-coded administrative account ('CEAdmin') with a password hash ('l0g1nnatick') stored in the configuration files that is identical across all deployments. A remote, unauthenticated attacker can use these credentials to access the WildFly management interface. Once authenticated, the attacker can upload and deploy a malicious Web Application Archive (WAR) file via the 'Deployments' interface to execute arbitrary code with the privileges of the Windows machine account. While version 14.x.x reached end-of-life in 2017, the vulnerability was formally disclosed in 2026.

Affected products

  • Care Everywhere LLC Care Everywhere Gateway 14.3.10 and prior

Timeline

  • 2017: other: Version 14.x.x declared end-of-life (EOL)
  • 2026-07-29: disclosed: Vulnerability details and PoC published by researcher
  • 2026-07-29: advisory: CVE-2026-41939 published

References