Description
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Archive file through the Deployments interface to achieve remote code execution as the Windows machine account. Version 14.x.x was declared end-of-life (EOL) in 2017 and future releases have addressed the vulnerable finding.
Published: 2026-07-29
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Care Everywhere Gateway version 14.3.10, where the bundled WildFly 8.2.0.Final management console uses hard‑coded default credentials. An unauthenticated attacker can log in to the console on port 20990 and deploy a malicious web archive via the Deployments interface. Successful deployment gives the attacker the ability to execute arbitrary code with the privileges of the Windows machine account, effectively compromising the host.

Affected Systems

Care Everywhere Gateway from Care Everywhere LLC, specifically version 14.3.10 of the 14.x.x series, is affected. The entire 14.x.x line was declared end‑of‑life in 2017 and is no longer supported; newer releases of the product have removed the vulnerable WildFly component.

Risk and Exploitability

The CVSS score of 9.3 marks the flaw as critical, while an EPSS score of less than 1 % indicates a low current exploitation probability. The vulnerability is not yet listed in the CISA KEV catalog. Attackers only need to reach the open WildFly management port 20990 over the network and supply the known default credentials to gain full administrative access. From there, deploying a malicious WAR file results in remote code execution under the Windows machine account.

Generated by OpenCVE AI on August 4, 2026 at 12:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Care Everywhere Gateway to a supported release where the hard‑coded credentials have been removed.
  • If an upgrade is not immediately feasible, disable or remove the WildFly management console or block inbound traffic to port 20990 with a firewall.
  • As a temporary measure, change the default WildFly credentials by editing the user configuration or isolate the management port behind a trusted network segment.

Generated by OpenCVE AI on August 4, 2026 at 12:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Care Everywhere Llc
Care Everywhere Llc care Everywhere Gateway
Vendors & Products Care Everywhere Llc
Care Everywhere Llc care Everywhere Gateway
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Archive file through the Deployments interface to achieve remote code execution as the Windows machine account. Version 14.x.x was declared end-of-life (EOL) in 2017 and future releases have addressed the vulnerable finding.
Title Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly
Weaknesses CWE-1392
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Care Everywhere Llc Care Everywhere Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-30T13:58:58.433Z

Reserved: 2026-04-22T18:50:43.621Z

Link: CVE-2026-41939

cve-icon Vulnrichment

Updated: 2026-07-30T13:57:50.101Z

cve-icon NVD

Status : Deferred

Published: 2026-07-29T18:16:53.477

Modified: 2026-07-30T16:45:00.353

Link: CVE-2026-41939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T12:30:09Z

Weaknesses