What is CVE-2026-50578?
CVE-2026-50578 is a critical vulnerability in ePA 3.x Integration, which handles authorization and writes Medical Information Objects to Germany's electronic patient record. Prior to version 1.3.0, TLS certificate verification is disabled for both ePA and Konnektor connections, creating a risk of medical data interception. Users should upgrade to version 1.3.0 or later immediately.
Azərbaycanca: CVE-2026-50578 ePA 3.x Integration proqramında aşkar edilmiş kritik zəiflikdir. 1.3.0 versiyasından əvvəlki versiyalarda həm ePA bağlantıları, həm də Konnektor əlaqələri üçün TLS sertifikat yoxlanışı deaktiv edilib ki, bu da xəstə məlumatlarının oğurlanması riski yaradır. İstifadəçilər dərhal 1.3.0 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What software is affected by CVE-2026-50578 and what is the main risk?
This critical vulnerability was discovered in ePA 3.x Integration. In versions prior to 1.3.0, TLS certificate verification is disabled, creating a risk of medical data interception.
What action should be taken to mitigate CVE-2026-50578?
Users should upgrade to version 1.3.0 or later immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.