TLS Certificate Vulnerability in epa4all by med-united
CVE-2026-54342

8.1HIGH

Key Information:

Vendor

Med-united

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-54342?

In the epa4all application, prior to version 2026-05-20, a network attacker could exploit a vulnerability by presenting a self-signed TLS certificate. This would allow them to intercept and manipulate communications between epa4all and various backend services, such as ePA Aktensystem, Konnektor, IDP, and TSS. This vulnerability impacts the integrity of the data transmitted during critical processes, including smartcard interactions and OIDC authentication. The issue has been addressed and resolved in the latest update.

Affected Version(s)

epa4all < 2026-05-20

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.