Executive brief
epa4all is a software component used to connect medical practices to the German electronic patient record (ePA) infrastructure. A security flaw was discovered where the software fails to verify the identity of the servers it connects to, allowing an attacker on the local network to intercept and modify sensitive communications. This could result in the exposure of patient medical records, document contents, and authentication credentials, potentially compromising the privacy of any patient managed by the affected system.
Technical details
The epa4all application prior to version 2026-05-20 contains a vulnerability where TLS certificate and hostname verification are explicitly disabled. Specifically, SSLUtils.createFakeSSLContext() and getFakeTrustManagers() implement an X509TrustManager with empty validation methods, and the system property 'jdk.internal.httpclient.disableHostnameVerification' is set to true. An attacker positioned on the network path (typically the clinical LAN) can perform a Man-in-the-Middle (MITM) attack using self-signed certificates. This allows for the interception and modification of traffic to the ePA Aktensystem, Konnektor, and IDP, including OIDC authentication exchanges and smartcard (SMC-B) operations. The issue is patched in version 2026-05-20, which restores verification using a Telematik-TSL-based keystore.
Affected products
- med-united epa4all < 2026-05-20
Timeline
- 2026-05-20: patched: Fix released in version 2026-05-20
- 2026-05-20: disclosed: Initial disclosure to vendor
- 2026-07-24: advisory: CVE-2026-54342 published