Vulnary
← back to the feed
Critical· 9.3official fix available

CVE-2026-41939

Care Everywhere Gateway 14.3.10 contains a hard‑coded credentials flaw in its bundled WildFly 8.2.0.Final management interface. Unauthenticated attackers can log in with default credentials, deploy a malicious web archive, and execute code as the Windows machine account. The vulnerability is critical with a CVSS score of 9.3.

publishedJul 29, 2026
last modifiedJul 29, 2026
sourcesNVD
severity · cvss
9.3
critical · how bad it is
exploitation · epss
n/a
chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 28, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Care Everywhere Gateway version 14.3.10 (and any 14.x.x releases) running on Windows, typically used by healthcare institutions.

02

Real-world impact

An attacker can gain administrative access, deploy malicious code, and run arbitrary commands on the Windows machine.

03

Why this severity

The CVSS score of 9.3 reflects the ability to remotely execute code with full system privileges, compromising confidentiality, integrity, and availability of the affected system.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade Care Everywhere Gateway to a version newer than 14.3.10 that removes the hard‑coded credentials.
  2. 02Verify that the WildFly management console no longer accepts default credentials.

NVD-referenced vendor advisory

05

Timeline

  1. Jul 29, 2026 · 17h ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 29, 2026 · 16h ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →