CVE-2026-54342 Details
Description
In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnektor, IDP), this allows direct read and modification of the inner traffic, including smartcard operations and OIDC authentication exchanges. For the ePA backend, the disabled TLS verification is the transport-level enabler for the VAU MITM described in GHSA-vvh7-x6c7-46gh. This issue has been patched in version 2026-05-20.
A vulnerability in ePA4all prior to version 2026-05-20 allows an attacker on the network path to intercept connections by presenting a self-signed TLS certificate. This issue arises from disabled TLS verification, which is applied to all CXF transport clients and affects non-VAU connections with the Konnektor and IDP. The vulnerability enables direct reading and modification of inner traffic, including smartcard operations and OIDC authentication exchanges. For the ePA backend, the lack of proper TLS verification facilitates a VAU man-in-the-middle attack, as detailed in a related advisory.
Users should update to ePA4all version 2026-05-20 or later, which restores proper TLS verification by adding hostname and certificate checks, and pins the gematik TI PKI via a Telematik-TSL-based keystore. After updating, verify that the trust store includes the TI PKI roots and that no permissive hostname verifiers are present.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 24, 2026CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/med-united/epa4all/releases/tag/2026-05-20 | [email protected] | Release NotesVendor |
| https://github.com/med-united/epa4all/security/advisories/GHSA-296w-v8f6-3rf7 | [email protected] | AdvisoryRemedyVendor |
| https://github.com/med-united/epa4all/security/advisories/GHSA-vvh7-x6c7-46gh | [email protected] | AdvisoryBundleRemedyVendor |
| https://www.machinespirits.com/advisory/b98b02 | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| med-united epa4all | 1.0.0-SNAPSHOT (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 24, 2026 | New CVE Received | [email protected] |
Volerion