What is CVE-2026-52723?
This vulnerability exists in ePA 3.x Integration due to improper VAU server certificate validation without anchoring to `signed_vau_server_pub_keys`. Affecting systems that write Medical Information Objects to Germany's electronic patient record, versions prior to 1.3.0 are impacted. Immediate update to version 1.3.0 or later is required.
Azərbaycanca: Bu boşluq ePA 3.x Integration proqramında VAU server sertifikatının düzgün təsdiqlənməməsi ilə bağlıdır. Almaniyanın elektron xəstə qeydlərinə tibbi məlumat yazan bu həll, 1.3.0 versiyasına qədər sertifikat zəncirini `signed_vau_server_pub_keys`-ə lövbərləmədən yoxlayır. Təsirə məruz qalan qurumlar dərhal 1.3.0 və ya daha yuxarı versiyaya yeniləməlidir.
FAQ2
Which versions of ePA 3.x Integration are affected by CVE-2026-52723?
The vulnerability affects versions of ePA 3.x Integration prior to 1.3.0.
What is the root cause of CVE-2026-52723?
The root cause is improper VAU server certificate validation without anchoring to `signed_vau_server_pub_keys`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.