Security Flaw in ePA 3.x Integration Allows Unauthorized Access
CVE-2026-52723

9.1CRITICAL

Key Information:

Vendor

Fbeta-gmbh

Vendor
CVE Published:
18 August 2026

What is CVE-2026-52723?

The ePA 3.x Integration component, which interfaces with Germany's electronic patient records, exposes a significant vulnerability due to improper certificate validation. Versions prior to 1.3.0 fail to properly anchor signed server certificate paths to trusted materials, allowing a malicious actor to intercept communications between the DiGA backend and the ePA system. This can lead to the attacker impersonating the VAU server, gaining control of session keys, and accessing or altering sensitive encrypted traffic. The vulnerability is mitigated in version 1.3.0.

Affected Version(s)

ePA3-Service-OpenSource < 1.3.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.