CVE-2026-52723

Source
https://cve.org/CVERecord?id=CVE-2026-52723
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-52723.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-52723
Aliases
  • GHSA-q2jw-6c4w-86jc
Published
2026-08-18T16:50:49.799Z
Modified
2026-08-20T03:54:25.572309693Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
ePA 3.x Integration: VAU Server Authentication Bypass via Circular Certificate Trust
Details

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration performs VAU server certificate validation in app/vau/VAUProtokoll.py without anchoring the signedvauserverpubkeys and AUTVAUCertData certificate path to independent trusted material. A network-positioned attacker between the DiGA backend and the ePA system can intercept the VAU handshake, supply attacker-controlled certificate and key material, and satisfy the circular trust relationship. Because TLS certificate verification is also disabled in affected versions, no independent server-authentication layer prevents the attack. The attacker can impersonate the VAU server, control the negotiated session keys, and read or modify all encrypted VAU traffic. This issue is fixed in version 1.3.0.

Database specific
{
    "cwe_ids": [
        "CWE-295"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52723.json"
}
References

Affected packages

Git / github.com/fbeta-gmbh/epa3-service-opensource

Affected ranges

Type
GIT
Repo
https://github.com/fbeta-gmbh/epa3-service-opensource
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.3.0"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-52723.json"