CVE-2026-47672: Oviva-AG EPA4ALL-Client

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any network-reachable caller can write arbitrary documents to any patient's electronic health record accessible by the institution's SMC-B card. In a misconfigured deployment (e.g., following the production Docker example in the README), this is exploitable from the local network without credentials.

Affected products

  • Oviva-AG EPA4ALL-Client: up to and including 1.2.4

Published 2026-05-26. Last modified 2026-07-24.