CVE-2026-50577
Last modified
CVE-2026-50577 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration leaves request_counter unchanged in app/vau/VAUProtokoll.py while constructing VAU messages. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration leaves request_counter unchanged in app/vau/VAUProtokoll.py while constructing VAU messages. The frozen client request counter causes the server side to reuse AES-GCM nonce and key combinations across responses. A network attacker who collects repeated ciphertexts can recover the XOR of plaintexts and use predictable inner HTTP headers and JSON fields to recover sensitive data, including patient health records. Repeated nonces can also enable recovery of the GHASH authentication key through the Joux forbidden attack, allowing forged AES-GCM messages and injection of malicious responses. The response-counter check also fails to maintain last_response_counter, weakening replay and ordering validation. This issue is fixed in version 1.3.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| fbeta-GmbH | ePA3-Service-OpenSource | < 1.3.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-50577?
How severe is CVE-2026-50577?
How do I fix CVE-2026-50577?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-50570Fission is an open-source, Kubernetes-native serverless fram…8.5
- CVE-2026-50572Envoy is an open source edge and service proxy designed for …5.9
- CVE-2026-50573pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnp…8.1
- CVE-2026-50574yt-dlp is a command-line audio/video downloader. Prior to 20…9.6
- CVE-2026-50575BetterDesk is a remote desktop management solution. BetterDe…7.7
- CVE-2026-50576ePA 3.x Integration implements the authorization workflow an…6.8
- CVE-2026-50578ePA 3.x Integration implements the authorization workflow an…7.5
- CVE-2026-5058aws-mcp-server Command Injection Remote Code Execution Vulne…9.8
- CVE-2026-50589In OpenStack Ironic 32 before 37.0.0, an unauthenticated mal…7.5
- CVE-2026-5059aws-mcp-server AWS CLI Command Injection Remote Code Executi…9.8
- CVE-2026-50590In Mimecast Incydr before 2.6.0, arbitrary file access can o…4.5
- CVE-2026-50591In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can o…5.4
Are you affected by CVE-2026-50577?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
