Impact
Prior to version 2026-05-20, epa4all does not perform TLS and hostname validation during the VAU handshake; an attacker who can intercept the TLS connection between an epa4all client and the ePA backend can complete the handshake with attacker‑controlled keys, capture the session encryption keys, and decrypt all subsequent HTTPS traffic. The attacker can read and modify patient consent decisions, medication data, document operations, authorization tokens, and entitlement queries, and inject arbitrary requests through the hijacked channel.
Affected Systems
All med‑united epa4all clients running a build older than 2026-05-20 are affected. These releases lack the required TLS and hostname verification and therefore are vulnerable.
Risk and Exploitability
The CVSS score of 9.1 classifies this flaw as Critical, while the EPSS score of less than 1% indicates a very low exploitation probability. The vulnerability is not listed in CISA KEV. An attacker only needs the ability to intercept traffic between the client and the backend, which can be achieved by proximity or by compromising routers. Once positioned, the flaw can be used to read sensitive data and inject malicious requests, potentially leading to severe data exposure and unauthorized actions. No public exploits have been reported, but the high impact and low exploitation likelihood still warrant immediate remediation.
OpenCVE Enrichment