CVE-2026-45575
Last modified
CVE-2026-45575 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. The forged document redirects uri_puk_idp_enc and uri_puk_idp_sig to attacker-controlled URLs. The client then encrypts the SMC-B-signed challenge response to the attacker's encryption key and POSTs it to the attacker's auth endpoint. This captures the signed authentication material. This vulnerability is fixed in 1.2.2.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-45575?
How severe is CVE-2026-45575?
How do I fix CVE-2026-45575?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4557A vulnerability was detected in code-projects Exam Form Subm…4.3
- CVE-2026-45570go-git is an extensible git implementation library written i…9.6
- CVE-2026-45571go-git is an extensible git implementation library written i…5.4
- CVE-2026-45572Decidim is a participatory democracy framework. Prior to 0.3…4.8
- CVE-2026-45573Decidim is a participatory democracy framework. Prior to 0.3…6.4
- CVE-2026-45574epa4all-client is the Java Client for epa4all / ePA 3.0 in t…8.1
- CVE-2026-45576zrok is software for sharing web services, files, and networ…7.5
- CVE-2026-45577Neotoma provides versioned records that persist across agent…6.9
- CVE-2026-45578WWBN AVideo is an open source video platform. In 29.0 and ea…8.8
- CVE-2026-45579DIRAC is an interware, meaning a software framework for dist…9.9
- CVE-2026-4558A flaw has been found in Linksys MR9600 2.0.6.206937. Affect…8.8
- CVE-2026-45580WWBN AVideo is an open source video platform. In 29.0 and ea…5.4
Are you affected by CVE-2026-45575?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
