CVE-2026-54342
Received Received - Intake

TLS Certificate Validation Bypass in epa4all

Vulnerability report for CVE-2026-54342, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: GitHub, Inc.

Description

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnektor, IDP), this allows direct read and modification of the inner traffic, including smartcard operations and OIDC authentication exchanges. For the ePA backend, the disabled TLS verification is the transport-level enabler for the VAU MITM described in GHSA-vvh7-x6c7-46gh. This issue has been patched in version 2026-05-20.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-25
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
epa4all epa4all to 2026-05-20 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

In epa4all versions before 2026-05-20, an attacker on the network path can intercept communications by presenting a self-signed TLS certificate. This allows them to read and modify traffic between epa4all and backend systems like ePA Aktensystem, Konnektor, IDP, and TSS. For non-VAU connections, this includes smartcard operations and authentication exchanges. The issue is patched in version 2026-05-20.

Detection Guidance

Detecting this vulnerability requires checking if epa4all is running a version prior to 2026-05-20. Inspect the installed version of epa4all on your system. If the version is older than 2026-05-20, the system is vulnerable. No specific commands are provided in the context.

Impact Analysis

An attacker could intercept sensitive data, modify communications, or impersonate backend systems. This could lead to unauthorized access, data theft, or manipulation of transactions. Users relying on epa4all for secure communications may face compromised confidentiality and integrity of their data.

Compliance Impact

This vulnerability could lead to unauthorized access or disclosure of personal data, violating GDPR's principles of confidentiality and integrity. For HIPAA, it may compromise protected health information, risking breaches of security and privacy requirements. Organizations using affected versions may fail compliance audits.

Mitigation Strategies

Immediately update epa4all to version 2026-05-20 or later. Ensure TLS verification is enabled for all connections to backend systems (ePA Aktensystem, Konnektor, IDP, TSS). For non-VAU connections, enforce strict TLS validation to prevent interception.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54342. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart