CVE-2026-45574 PUBLISHED

epa4all-client: TLS Certificate Validation Disabled in Production

Assigner: GitHub_M
Reserved: 12.05.2026 Published: 26.05.2026 Updated: 27.05.2026

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient identifiers (KVNR), SMC-B card operations (authentication, signing), document content, and credential exchanges. This vulnerability is fixed in 1.2.2.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Score: 8.1

Product Status

Vendor oviva-ag
Product epa4all-client
Versions
  • Version < 1.2.2 is affected
Vendor com.oviva.telematik
Product epa4all-client
Versions
  • Version < 1.2.2 is affected

References

Problem Types

  • CWE-295: Improper Certificate Validation CWE