Junglewise Threat Intelligence

CVE-2026-47672: Oviva epa4all-client missing authentication for patient record writes

CVE-2026-47672 · Severity: medium · CVSS 6.5 · Published 2026-05-26

Technologies: Oviva Epa4all-Rest-Service. Vendors: Maven, Oviva, Oviva AG.

Executive brief

A vulnerability in the epa4all-client REST service allows unauthorized users on the same network to write data to patient electronic health records. This component is used to interface with medical record systems, and an exploit could allow an attacker to inject fraudulent medical documents or alter existing patient history. This poses a significant risk to data integrity and patient safety within healthcare environments.

Technical details

The epa4all-client (specifically the epa4all-rest-service) suffers from missing authentication (CWE-306) for critical REST API endpoints. Any attacker reachable via the network (typically the local or adjacent network in standard deployments) can write arbitrary documents to any patient's electronic health record accessible by the institution's SMC-B card. This is particularly exploitable in deployments following the default production Docker examples which may lack external authentication layers. Attackers can achieve full integrity loss of patient records. A patch is available in the project's repository, and workarounds include implementing mTLS or isolating the service within a Kubernetes sidecar or service mesh.

Affected products

  • oviva-ag epa4all-rest-service <= 1.2.4

Timeline

  • 2026-05-19: disclosed: Initial disclosure by Oviva AG
  • 2026-05-26: advisory: NVD publication date
  • 2026-06-04: advisory: GitHub Advisory Database publication date

References

Related threats