Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-48021: epa4all: Data Exposure and Manipulation via TLS Interception

CVE-2026-48021 CVE-2026-48021
Summary

A previous version of epa4all allowed an attacker to intercept sensitive data and modify it. This happened because the software didn't properly check the identity of the server it was communicating with. The issue has been fixed in a later version, but you should update to the latest version to be secure.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
med-united epa4all < 2026-05-20
Original title
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain...
Original description
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions, medication data, document operations, authorization tokens, and entitlement queries) becomes readable and modifiable. The attacker can also inject arbitrary requests through the hijacked channel. This issue has been patched in version 2026-05-20.
mitre CVSS3.1 9.1
Vulnerability type
CWE-295 Improper Certificate Validation
CWE-347 Improper Verification of Cryptographic Signature
Published: 24 Jul 2026 · Updated: 25 Jul 2026 · First seen: 24 Jul 2026