PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-52723 fbeta-GmbH CVE debrief

A critical vulnerability was found in ePA 3.x Integration prior to version 1.3.0, allowing a network-positioned attacker to impersonate the VAU server, control session keys, and read or modify encrypted VAU traffic due to improper VAU server certificate validation and disabled TLS certificate verification. This issue arises from the integration's failure to anchor the signed_vau_server_pub_keys and AUT_VAU_CertData certificate path to independent trusted material, combined with the lack of TLS certificate verification. As a result, an attacker can intercept the VAU handshake, supply attacker-controlled certificate and key material, and satisfy the circular trust relationship. The e

Vendor
fbeta-GmbH
Product
ePA3-Service-OpenSource
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-09-08
Advisory published
2026-08-18
Advisory updated
2026-09-08

Who should care

Defenders of systems using ePA 3.x Integration, especially those in Germany's electronic patient record system, should assess exposure and prioritize upgrading to version 1.3.0. This involves reviewing the current deployment of ePA 3.x Integration, identifying potential vulnerabilities, and implementing necessary updates or mitigations. Additionally, defenders should verify VAU server certificate validation and TLS certificate verification, and monitor for

Why it matters

CVE-2026-52723 allows a network-positioned attacker to impersonate the VAU server and control encrypted traffic due to improper certificate validation and disabled TLS verification in ePA 3.x Integration prior to version 1.3.0. Defenders of systems using ePA 3.x Integration should assess exposure and prioritize upgrading to version 1.3.0.

  • Impersonation of VAU server by a network-positioned attacker
  • Control of negotiated session keys by an attacker
  • Reading or modification of encrypted VAU traffic by an attacker
  • Verification of certificate validation and TLS certificate verification in ePA 3.x Integration systems

Technical summary

ePA 3.x Integration prior to version 1.3.0 performs VAU server certificate validation without anchoring the signed_vau_server_pub_keys and AUT_VAU_CertData certificate path to independent trusted material. A network-positioned attacker can intercept the VAU handshake, supply attacker-controlled certificate and key material, and satisfy the circular trust relationship. TLS certificate verification is also disabled in affected versions.

Defensive priority

High priority for systems using ePA 3.x Integration, especially those in Germany's electronic patient record system, to upgrade to version 1.3.0 and verify certificate validation.

Recommended defensive actions

  • Upgrade ePA 3.x Integration to version 1.3.0 or later
  • Verify VAU server certificate validation and TLS certificate verification
  • Monitor for suspicious VAU traffic and session key activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source references indicate a critical vulnerability in ePA 3.x Integration prior to version 1.3.0. The issue is related to improper VAU server certificate validation and disabled TLS certificate verification.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-52723 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-52723

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-52723 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52723

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.