Authorization Flaw in ePA 3.x Integration Could Lead to Data Exposure
CVE-2026-50576

6.8MEDIUM

Key Information:

Vendor

Fbeta-gmbh

Vendor
CVE Published:
18 August 2026

What is CVE-2026-50576?

The ePA 3.x Integration prior to version 1.3.0 is vulnerable due to improper handling of CRLF characters in user-controlled values used for building inner HTTP requests. This flaw enables authenticated attackers to manipulate HTTP headers, potentially leading to unauthorized access to sensitive medical records of other patients. Specifically, attackers can inject headers such as x-insurantid, which may expose patient data, or modify Authorization headers to circumvent established authentication and authorization mechanisms. The use of session-derived USER_AGENT variables may also lead to request poisoning. This vulnerability has been remedied in version 1.3.0.

Affected Version(s)

ePA3-Service-OpenSource < 1.3.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.