PatchSiren cyber security CVE debrief
CVE-2026-52723 fbeta-GmbH CVE debrief
A critical vulnerability was found in ePA 3.x Integration prior to version 1.3.0, allowing a network-positioned attacker to impersonate the VAU server, control session keys, and read or modify encrypted VAU traffic due to improper VAU server certificate validation and disabled TLS certificate verification. This issue arises from the integration's failure to anchor the signed_vau_server_pub_keys and AUT_VAU_CertData certificate path to independent trusted material, combined with the lack of TLS certificate verification. As a result, an attacker can intercept the VAU handshake, supply attacker-controlled certificate and key material, and satisfy the circular trust relationship. The e
- Vendor
- fbeta-GmbH
- Product
- ePA3-Service-OpenSource
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-09-08
Who should care
Defenders of systems using ePA 3.x Integration, especially those in Germany's electronic patient record system, should assess exposure and prioritize upgrading to version 1.3.0. This involves reviewing the current deployment of ePA 3.x Integration, identifying potential vulnerabilities, and implementing necessary updates or mitigations. Additionally, defenders should verify VAU server certificate validation and TLS certificate verification, and monitor for
Why it matters
CVE-2026-52723 allows a network-positioned attacker to impersonate the VAU server and control encrypted traffic due to improper certificate validation and disabled TLS verification in ePA 3.x Integration prior to version 1.3.0. Defenders of systems using ePA 3.x Integration should assess exposure and prioritize upgrading to version 1.3.0.
- Impersonation of VAU server by a network-positioned attacker
- Control of negotiated session keys by an attacker
- Reading or modification of encrypted VAU traffic by an attacker
- Verification of certificate validation and TLS certificate verification in ePA 3.x Integration systems
Technical summary
ePA 3.x Integration prior to version 1.3.0 performs VAU server certificate validation without anchoring the signed_vau_server_pub_keys and AUT_VAU_CertData certificate path to independent trusted material. A network-positioned attacker can intercept the VAU handshake, supply attacker-controlled certificate and key material, and satisfy the circular trust relationship. TLS certificate verification is also disabled in affected versions.
Defensive priority
High priority for systems using ePA 3.x Integration, especially those in Germany's electronic patient record system, to upgrade to version 1.3.0 and verify certificate validation.
Recommended defensive actions
- Upgrade ePA 3.x Integration to version 1.3.0 or later
- Verify VAU server certificate validation and TLS certificate verification
- Monitor for suspicious VAU traffic and session key activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source references indicate a critical vulnerability in ePA 3.x Integration prior to version 1.3.0. The issue is related to improper VAU server certificate validation and disabled TLS certificate verification.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-52723 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-52723
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-52723 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52723
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/fbeta-GmbH/ePA3-Service-OpenSource/commit/197c8c7fc41675f19c7f448696a2bc63fab9db5b
-
Source reference
Unverified legacy reference
URL: https://github.com/fbeta-GmbH/ePA3-Service-OpenSource/pull/12
-
Source reference
Unverified legacy reference
URL: https://github.com/fbeta-GmbH/ePA3-Service-OpenSource/releases/tag/1.3.0
-
Source reference
Unverified legacy reference
URL: https://github.com/fbeta-GmbH/ePA3-Service-OpenSource/security/advisories/GHSA-q2jw-6c4w-86jc
-
Source reference
Unverified legacy reference
URL: https://www.machinespirits.de/advisory/a1da93
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.