CVE-2026-41939

CRITICAL

Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly

Title source: cna
STIX 2.1

Description

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Archive file through the Deployments interface to achieve remote code execution as the Windows machine account. Version 14.x.x was declared end-of-life (EOL) in 2017 and future releases have addressed the vulnerable finding.

References (3)

Core 3
Core References
Exploit technical-description exploit
Researcher Disclosure
https://gist.github.com/VAMorales/95874f23e27e17362b87133013834c0a
Product product
Parent Company Products Page
https://www.intuvie.com/products-overview

Scores

CVSS v3 9.8
EPSS 0.0080
EPSS Percentile 53.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-1392
Status published
Products (1)
Care Everywhere LLC/Care Everywhere Gateway 14.3.10
Published Jul 29, 2026
Tracked Since Jul 29, 2026