PT-2026-64406 · Epa4All · Epa4All

CVE-2026-48021

·

Published

2026-07-24

·

Updated

2026-07-25

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions epa4all versions prior to 2026-05-20
Description An attacker capable of intercepting the TLS connection between the application and the ePA backend can complete the VAU handshake using attacker-controlled keys to obtain session encryption keys. This allows the attacker to read and modify all inner HTTP traffic, including medication data, patient consent decisions, document operations, entitlement queries, and authorization tokens. Additionally, the attacker can inject arbitrary requests through the hijacked channel.
Recommendations Update to version 2026-05-20.

Exploit

Fix

Improper Verification of Cryptographic Signature

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48021
GHSA-VVH7-X6C7-46GH

Affected Products

Epa4All