Network Path Vulnerability in epa4all-client Java Client for Telematik Infrastruktur
CVE-2026-45574
8.1HIGH
What is CVE-2026-45574?
The epa4all-client is a Java application designed for the epa4all service used in the Telematik Infrastruktur. Prior to version 1.2.2, a vulnerability existed that allowed an attacker to exploit the network path between the ePA service and the Konnektor. This exploit enabled the attacker to present any TLS certificate—whether self-signed, expired, or with an incorrect Common Name (CN)—allowing them to intercept all SOAP traffic. This includes sensitive information such as patient identifiers, SMC-B card operations, document content, and credential exchanges. A patch was released in version 1.2.2 to address this security issue.
Affected Version(s)
epa4all-client < 1.2.2
epa4all-client < 1.2.2
