TLS Certificate Vulnerability in epa4all by med-united
CVE-2026-54342
8.1HIGH
What is CVE-2026-54342?
In the epa4all application, prior to version 2026-05-20, a network attacker could exploit a vulnerability by presenting a self-signed TLS certificate. This would allow them to intercept and manipulate communications between epa4all and various backend services, such as ePA Aktensystem, Konnektor, IDP, and TSS. This vulnerability impacts the integrity of the data transmitted during critical processes, including smartcard interactions and OIDC authentication. The issue has been addressed and resolved in the latest update.
Affected Version(s)
epa4all < 2026-05-20
