Authorization Flaw in ePA 3.x Integration Could Lead to Data Exposure
CVE-2026-50576
6.8MEDIUM
What is CVE-2026-50576?
The ePA 3.x Integration prior to version 1.3.0 is vulnerable due to improper handling of CRLF characters in user-controlled values used for building inner HTTP requests. This flaw enables authenticated attackers to manipulate HTTP headers, potentially leading to unauthorized access to sensitive medical records of other patients. Specifically, attackers can inject headers such as x-insurantid, which may expose patient data, or modify Authorization headers to circumvent established authentication and authorization mechanisms. The use of session-derived USER_AGENT variables may also lead to request poisoning. This vulnerability has been remedied in version 1.3.0.
Affected Version(s)
ePA3-Service-OpenSource < 1.3.0
