PT-2026-77223 · Epa · Epa

CVE-2026-52723

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ePA 3.x Integration versions prior to 1.3.0
Description The software performs VAU server certificate validation in the app/vau/VAUProtokoll.py file without anchoring the signed vau server pub keys and AUT VAU CertData certificate path to independent trusted material. Additionally, TLS certificate verification is disabled. A network-positioned attacker between the DiGA backend and the ePA system can intercept the VAU handshake and provide attacker-controlled certificate and key material to satisfy a circular trust relationship. This allows the attacker to impersonate the VAU server, control negotiated session keys, and read or modify all encrypted VAU traffic.
Recommendations Update to version 1.3.0.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52723
GHSA-Q2JW-6C4W-86JC

Affected Products

Epa