Security Flaw in ePA 3.x Integration Allows Unauthorized Access
CVE-2026-52723
9.1CRITICAL
What is CVE-2026-52723?
The ePA 3.x Integration component, which interfaces with Germany's electronic patient records, exposes a significant vulnerability due to improper certificate validation. Versions prior to 1.3.0 fail to properly anchor signed server certificate paths to trusted materials, allowing a malicious actor to intercept communications between the DiGA backend and the ePA system. This can lead to the attacker impersonating the VAU server, gaining control of session keys, and accessing or altering sensitive encrypted traffic. The vulnerability is mitigated in version 1.3.0.
Affected Version(s)
ePA3-Service-OpenSource < 1.3.0
