CVE-2026-50578: ePA 3.x Integration: TLS Certificate Verification Universally Disabled

Published Aug 18, 2026
·
Updated

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration disables TLS certificate verification for both ePA connections in app/vau/VAUProtokoll.py and Konnektor connections in app/konnektor/Konnektor.py. A network-positioned attacker can present an arbitrary certificate, terminate the TLS connection, and intercept ePA traffic. The VAU protocol does not provide an effective fallback because its application-layer certificate validation is also broken in affected versions. The Konnektor session uses self.session.verify set to False while the client authenticates with self.session.cert, so an attacker impersonating the Konnektor can receive the client's mutual TLS certificate exchange and observe smartcard operations. This issue is fixed in version 1.3.0.

Affected Software

1 affected component
ePA 3.x Integration<1.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ePA 3.x Integration to a version that resolves this vulnerability.

    Fixed in 1.3.0

Event History

Aug 18, 2026
CVE Published
via MITRE·04:51 PM
Data Sourced
via MITRE·04:51 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments need remediation?

Deployments running versions prior to 1.3.0 are affected. Version 1.3.0 fixes the issue.

2

What access does an attacker need to exploit this?

A network-positioned attacker can exploit the issue without authentication or user interaction by presenting an arbitrary certificate and terminating the TLS connection. This can expose ePA traffic and allow impersonation of the Konnektor.

3

Does the VAU protocol mitigate the disabled TLS verification?

The affected code disables TLS certificate verification for both ePA and Konnektor connections, and the VAU protocol's application-layer certificate validation is also broken. As a result, the described workflow does not provide an effective certificate-validation safeguard in affected versions.

4

What information or operations could be exposed?

An attacker impersonating the Konnektor can receive the client's mutual TLS certificate exchange and observe smartcard operations. The issue can also allow interception of ePA traffic, including traffic related to authorization workflows and Medical Information Objects.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203