PT-2026-39308 · Unknown · Epa4All-Client

Chiara Fliegner

+2

·

Published

2026-05-08

·

Updated

2026-05-27

·

CVE-2026-44900

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions epa4all-client (affected versions not specified)
Description A signature bypass exists in the isTrusted() function of the SignedPublicKeysTrustValidatorImpl class. The ECDSA signature verification process discards the boolean return value of the Signature.verify() function. Although the system performs certificate chain validation, OCSP checks, and signature algorithm setup, it fails to verify if the signature actually matches, resulting in the function returning true for any structurally valid signature.
Recommendations Update to the version that includes the fix provided in pull request #34.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44900
GHSA-G8R3-5HWF-QP96

Affected Products

Epa4All-Client