Critical severity9.8NVD Advisory· Published Jul 29, 2026· Updated Jul 30, 2026
CVE-2026-41939
CVE-2026-41939
Description
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Archive file through the Deployments interface to achieve remote code execution as the Windows machine account. Version 14.x.x was declared end-of-life (EOL) in 2017 and future releases have addressed the vulnerable finding.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <14.3.10
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.