CVE-2026-33874

Source
https://cve.org/CVERecord?id=CVE-2026-33874
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33874.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-33874
Aliases
  • GHSA-mjgm-7hwc-qqcr
Published
2026-03-27T20:23:53Z
Modified
2026-08-12T03:51:18Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Authenticator vulnerable to Remote Code Execution
Details

Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior to version 4.16.0, the Mac OS version of the Authenticator is vulnerable to remote code execution, triggered when victims open a malicious file. Update the gematik Authenticator to version 4.16.0 or greater to receive a patch. There are no known workarounds.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33874.json"
}
References

Affected packages

Git / github.com/gematik/app-authenticator

Affected ranges

Type
GIT
Repo
https://github.com/gematik/app-authenticator
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:gematik:authenticator:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "4.12.0"
        },
        {
            "fixed": "4.16.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

4.*
4.12.0
4.13.0
4.13.1
4.13.2
4.14.0
4.14.1
4.15.0
4.15.1
4.15.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33874.json"