CVE-2026-45574
Deferred Deferred - Pending Action
Remote Code Execution in epa4all-client Java Client

Publication date: 2026-05-26

Last updated on: 2026-05-26

Assigner: GitHub, Inc.

Description
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient identifiers (KVNR), SMC-B card operations (authentication, signing), document content, and credential exchanges. This vulnerability is fixed in 1.2.2.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-26
Last Modified
2026-05-26
Generated
2026-06-16
AI Q&A
2026-05-27
EPSS Evaluated
2026-06-14
NVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The vulnerability exists in epa4all-client, the Java client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Before version 1.2.2, an attacker positioned on the network path between the ePA service and the Konnektor can present any TLS certificateβ€”whether self-signed, expired, or with the wrong common nameβ€”and successfully intercept all SOAP traffic.

This means the attacker can perform a man-in-the-middle attack, bypassing TLS certificate validation, and capture sensitive data transmitted between the client and service.

Impact Analysis

This vulnerability allows an attacker to intercept sensitive information including patient identifiers (KVNR), SMC-B card operations such as authentication and signing, document content, and credential exchanges.

Such interception can lead to unauthorized access to confidential patient data, compromise of authentication mechanisms, and potential misuse of credentials, severely impacting data confidentiality and integrity.

Mitigation Strategies

To mitigate this vulnerability, you should upgrade the epa4all-client to version 1.2.2 or later, as this version fixes the issue where an attacker can present any TLS certificate and intercept SOAP traffic.

Compliance Impact

This vulnerability allows an attacker on the network path to intercept all SOAP traffic, including sensitive patient identifiers, authentication operations, document content, and credential exchanges. Such interception of sensitive personal health information could lead to non-compliance with data protection regulations like GDPR and HIPAA, which require the protection of personal and health data against unauthorized access and disclosure.

Specifically, the exposure of patient identifiers and health-related data through interception violates principles of confidentiality and data integrity mandated by these regulations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-45574. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart