


Perceptive Security
SOC/SIEM Consultancy

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthentica…
Published:
28 July 2026 at 22:00:00
Alert date:
29 July 2026 at 19:00:49
Source:
nvd.nist.gov
Enterprise Applications, Critical Infrastructure, Identity & Access
Care Everywhere Gateway version 14.3.10 contains a hard-coded credentials vulnerability in its bundled WildFly 8.2.0.Final management interface. The vulnerability allows unauthenticated remote attackers to gain administrative access using default credentials that are identical across all installations. Attackers can access the WildFly management console on port 20990 and deploy a malicious WAR file to achieve remote code execution as the Windows machine account. The affected version 14.x.x was declared end-of-life in 2017, meaning no patches will be issued for this branch. Newer versions of the product have addressed the vulnerability. The issue is particularly critical in healthcare environments where Care Everywhere Gateway is used for health information exchange. Exploitation requires network access to port 20990 but no authentication, making it relatively easy to exploit if the management interface is exposed.
Technical details
Mitigation steps:
Affected products:
Care Everywhere Gateway 14.3.10
WildFly 8.2.0.Final
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41939
https://gist.github.com/VAMorales/95874f23e27e17362b87133013834c0a
https://www.intuvie.com/products-overview
https://www.vulncheck.com/advisories/care-everywhere-gateway-hard-coded-credentials-rce-via-wildfly
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
