CVE-2026-33875 PUBLISHED

Authenticator Vulnerable to Authentication Flow Hijack

Assigner: GitHub_M
Reserved: 24.03.2026 Published: 27.03.2026 Updated: 27.03.2026

Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing attackers to authenticate with the identities of victim users who click on a malicious deep link. Update Gematik Authenticator to version 4.16.0 or greater to receive a patch. There are no known workarounds.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
CVSS Score: 9.3

Product Status

Vendor gematik
Product app-Authenticator
Versions
  • Version < 4.16.0 is affected

References

Problem Types

  • CWE-940: Improper Verification of Source of a Communication Channel CWE