CyberRota Analysis
AI-GeneratedA vulnerability in epa4all prior to version 2026-05-20 allows attackers to intercept TLS connections, enabling them to complete the VAU handshake with malicious keys and access session encryption keys. This compromise exposes sensitive inner HTTP traffic, including patient consent and medication data, to unauthorized reading and modification, while also allowing arbitrary request injection. Organizations using epa4all should prioritize patching to the latest version to mitigate this critical risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions, medication data, document operations, authorization tokens, and entitlement queries) becomes readable and modifiable. The attacker can also inject arbitrary requests through the hijacked channel. This issue has been patched in version 2026-05-20.