PT-2026-64407 · Epa4All · Epa4All

CVE-2026-54342

·

Published

2026-07-24

·

Updated

2026-07-24

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions epa4all versions prior to 2026-05-20
Description An attacker positioned on the network path between the software and any backend (ePA Aktensystem, Konnektor, IDP, or TSS) can intercept the connection by presenting a self-signed TLS certificate. For non-VAU connections, such as those with Konnektor or IDP, this allows the attacker to read and modify internal traffic, including OIDC authentication exchanges and smartcard operations. For the ePA backend, the lack of TLS verification serves as a transport-level enabler for a Man-in-the-Middle (MITM) attack.
Recommendations Update to version 2026-05-20.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54342
GHSA-296W-V8F6-3RF7
GHSA-VVH7-X6C7-46GH

Affected Products

Epa4All