CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-33875

CVSS 9.3v3.1pub. 2026-03-27upd. 2026-04-03

Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing attackers to authenticate with the identities of victim users who click on a malicious deep link. Update Gematik Authenticator to version 4.16.0 or greater to receive a patch. There are no known workarounds.

🤖 AI Analysis
How it works

An attacker prepares a malicious deep link and tricks the victim into clicking it. After clicking, authentication flow hijacking occurs, allowing the attacker to authenticate in the system using the victim's identity. The vulnerability results from improper verification of the source of the authentication request (CWE-940 – Improper Verification of Source of a Communication Channel).

Impact

An attacker can hijack the victim's identity and gain unauthorized access to digital health applications that the user logs into, which may lead to breaches of confidentiality and integrity of protected health data.

Mitigation & patch

Gematik Authenticator should be updated to version 4.16.0 or later. The vendor does not indicate any known workarounds for this vulnerability.

Who is affected

Gematik Authenticator in all versions earlier than 4.16.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Gematik Authenticator

    APP
    Gematik
    < 4.16.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-33874HIGH7.8same product

Gematik Authenticator securely authenticates users for login to digital health applications. Starting in versi...

CVE-2024-46984HIGH8.6same vendor

The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and int...