CVE-2026-41939
Care Everywhere Gateway 14.3.10 contains a hard‑coded credentials flaw in its bundled WildFly 8.2.0.Final management interface. Unauthenticated attackers can log in with default credentials, deploy a malicious web archive, and execute code as the Windows machine account. The vulnerability is critical with a CVSS score of 9.3.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Care Everywhere Gateway version 14.3.10 (and any 14.x.x releases) running on Windows, typically used by healthcare institutions.
Real-world impact
An attacker can gain administrative access, deploy malicious code, and run arbitrary commands on the Windows machine.
Why this severity
The CVSS score of 9.3 reflects the ability to remotely execute code with full system privileges, compromising confidentiality, integrity, and availability of the affected system.
What to do about it
- 01Upgrade Care Everywhere Gateway to a version newer than 14.3.10 that removes the hard‑coded credentials.
- 02Verify that the WildFly management console no longer accepts default credentials.
NVD-referenced vendor advisory
Timeline
- Jul 29, 2026 · 17h agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 16h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.