CVE-2026-41939
Deferred Deferred - Pending Action

Hard-Coded Credentials in Care Everywhere Gateway

Vulnerability report for CVE-2026-41939, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-30

Assigner: VulnCheck

Description

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Archive file through the Deployments interface to achieve remote code execution as the Windows machine account. Version 14.x.x was declared end-of-life (EOL) in 2017 and future releases have addressed the vulnerable finding.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-30
Generated
2026-08-19
AI Q&A
2026-07-30
EPSS Evaluated
2026-08-18
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
care_everywhere_gateway care_everywhere_gateway 14.3.10
wildfly wildfly 8.2.0_final

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1392 The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Care Everywhere Gateway 14.3.10 has a hard-coded credentials vulnerability in its bundled WildFly 8.2.0.Final management interface. This allows unauthenticated remote attackers to gain administrative access using default credentials that are the same across all installations. Attackers can access the WildFly management console on port 20990 and deploy a malicious Web Application Archive file to execute remote code as the Windows machine account.

Detection Guidance

Check if port 20990 is open on systems running Care Everywhere Gateway 14.3.10 or WildFly 8.2.0.Final. Use commands like 'nmap -p 20990 <target_IP>' or 'netstat -ano | findstr 20990' to detect the exposed management interface.

Impact Analysis

This vulnerability allows attackers to gain full administrative access to the system remotely without authentication. They can execute arbitrary code, potentially stealing data, installing malware, or disrupting operations. Since the affected version is end-of-life, no official patches are available.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and security such as GDPR and HIPAA due to unauthorized remote access and potential data breaches. Organizations using this software may face regulatory penalties and reputational damage.

Mitigation Strategies

Upgrade to a version of Care Everywhere Gateway beyond 14.x.x, as versions after 2017 have addressed this issue. Ensure the WildFly management interface is not exposed to untrusted networks and change default credentials if still present.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-41939. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart