What is CVE-2026-41939?
A hard-coded credentials vulnerability exists in the bundled WildFly 8.2.0.Final management interface within Care Everywhere Gateway 14.3.10. It allows unauthenticated remote attackers to gain administrative access using default credentials identical across all installations. Immediate network-level access restrictions and disabling default credentials are recommended until a vendor patch is available.
Azərbaycanca: Care Everywhere Gateway 14.3.10-un daxilindəki WildFly 8.2.0.Final idarəetmə interfeysində “hard-coded” etimadnamələri zəifliyi aşkar edilib. Bu boşluq autentifikasiya olunmamış uzaqdan təcavüzkara bütün qurğularda eyni olan standart parollar vasitəsilə administrator girişi əldə etməyə imkan verir. Dərhal şəbəkə səviyyəsində idarəetmə interfeysinə giriş məhdudlaşdırılmalı və istehsalçıdan yamaq təmin edilənə qədər standart etimadnamələr söndürülməlidir.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
Which product is affected by CVE-2026-41939?
This vulnerability affects the bundled WildFly 8.2.0.Final management interface within Care Everywhere Gateway 14.3.10.
What can an unauthenticated remote attacker gain by exploiting CVE-2026-41939?
An attacker can gain administrative access using default passwords that are identical across all installations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.