CVE-2026-48021 Details
Description
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions, medication data, document operations, authorization tokens, and entitlement queries) becomes readable and modifiable. The attacker can also inject arbitrary requests through the hijacked channel. This issue has been patched in version 2026-05-20.
A vulnerability in epa4all prior to version 2026-05-20 allows an attacker to intercept the TLS connection between epa4all and the ePA backend. This interception enables the attacker to complete the VAU handshake using their own keys, thereby obtaining session encryption keys. As a result, all inner HTTP traffic, including patient consent decisions, medication data, document operations, authorization tokens, and entitlement queries, becomes readable and modifiable. Additionally, the attacker can inject arbitrary requests through the compromised channel.
Users should update to version 2026-05-20 or later, ensuring that the TI PKI root certificates are properly loaded at runtime. After updating, verify that the VAU server authentication is functioning correctly by testing with a self-signed certificate that mimics an attacker's keys.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 24, 2026CISA-ADP
Assessed Jul 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/med-united/epa4all/releases/tag/2026-05-20 | [email protected] | Release NotesVendor |
| https://github.com/med-united/epa4all/security/advisories/GHSA-vvh7-x6c7-46gh | [email protected] | AdvisoryRemedyVendor |
| https://www.machinespirits.com/advisory/aa49f0 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| med-united epa4all | 1.0.0-SNAPSHOT (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 25, 2026 | CVE Modified | CISA-ADP |
| Jul 24, 2026 | New CVE Received | [email protected] |
Volerion