Junglewise Threat Intelligence

CVE-2026-82583: NextGen Connect SQL injection in Database Connector API

CVE-2026-82583 · Severity: high · CVSS 8.3 · Published 2026-09-11

Technologies: NextGen Connect.

Executive brief

NextGen Connect (Mirth Connect) is an open-source healthcare integration platform used to exchange data between medical systems and devices. An authenticated user can inject arbitrary SQL commands through the Database Connector API, potentially exposing stored credentials for connected systems, writing files to the server, or causing service outages that disrupt critical healthcare data flow.

Technical details

This is a SQL injection vulnerability in the Database Connector API of NextGen Connect versions 4.7.1 and earlier. The vulnerability requires authentication but allows an authenticated attacker to execute arbitrary SQL queries without proper input validation or parameterized query protection. Successful exploitation enables credential disclosure from the application's credential store, arbitrary file write operations on the server filesystem (potentially leading to code execution), and denial-of-service attacks through resource-intensive queries. A patch is expected from NextGen Connect for versions after 4.7.1.

Affected products

  • NextGen Connect 4.7.1 and earlier

Timeline

  • 2026-09-11: disclosed
  • 2026-09-11: advisory: CISA ICSMA-26-253-01

References