Roche disclosed CVE-2026-9844 in navify Digital Pathology 2.0.0 through 2.4.1, base score 8.8. The bundled RabbitMQ management interface ships with the default guest and guest credentials unless an operator changes them.
Default credentials are among the oldest weaknesses in networked software, and they persist because they make a product easy to install and demonstrate. A component that runs the moment it is switched on, with no configuration step, ships faster and generates fewer support calls. The convenience that eases the first hour of deployment becomes a standing liability for every hour after it.
In a digital pathology workflow the message broker is connective tissue, shuttling jobs and results between the parts that scan slides and the systems that store and read them. An interface granting management access to that bus is not a peripheral concern. Whoever holds it can observe the traffic that carries diagnostic material, interfere with its delivery, or reconfigure the queues the rest of the system relies on.
RabbitMQ ships guest:guest as a local-only convenience. Expose it on the network without changing it and you have handed over the message bus, and the maker owns that, not the customer. If you bundle a broker, a database or a runtime with a known default, disabling or rotating it is part of your product. Change every default credential before you ship, then verify the next release did not quietly reintroduce it.
The pattern reaches past any single product. Commercial medical software is increasingly assembled from open-source infrastructure that arrives with its own documented defaults. Each embedded piece carries the security posture its upstream authors chose for a developer's machine, not for a hospital network, and the assembler inherits that posture whether or not the integration notes ever mention it.