What is CVE-2026-54342?
CVE-2026-54384: In epa4all prior to version 2026-05-20, a Man-in-the-Middle (MitM) attacker on the network path can present a self-signed TLS certificate to intercept connections between epa4all and its backends, enabling reading and modification of data in non-VAU connections. Users should update to the latest version immediately.
FAQ2
Which versions of epa4all are affected by CVE-2026-54384?
The vulnerability affects versions of epa4all prior to 2026-05-20.
What can a network attacker achieve by exploiting CVE-2026-54384?
By presenting a self-signed TLS certificate, the attacker can intercept connections between epa4all and its backends, enabling reading and modification of data in non-VAU connections.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.