What is CVE-2026-48021?
CVE-2026-48021 is a vulnerability in epa4all where an attacker intercepting the TLS connection to the ePA backend can complete the VAU handshake with malicious keys, obtaining session encryption keys. This exposes inner HTTP traffic such as patient consent and medication data.
Azərbaycanca: CVE-2026-48021, epa4all proqramında TLS bağlantısı zəifliyidir. 2026-05-20 öncəsi versiyalarda, şəbəkə trafikini ələ keçirə bilən hücumçu VAU əl sıxışmasını öz açarları ilə tamamlayaraq seans şifrələmə açarlarını əldə edə bilər. Bu isə daxili HTTP trafikini (xəstə razılığı, dərman məlumatları) ifşa edir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of epa4all are affected by CVE-2026-48021?
Versions prior to 2026-05-20 are affected.
What internal data can be exposed by an attacker exploiting this vulnerability?
Sensitive data such as patient consent and medication information within the inner HTTP traffic can be exposed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.