PT-2026-39308 · Unknown · Epa4All-Client
Chiara Fliegner
+2
·
Published
2026-05-08
·
Updated
2026-05-27
·
CVE-2026-44900
CVSS v3.1
8.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
epa4all-client (affected versions not specified)
Description
A signature bypass exists in the
isTrusted() function of the SignedPublicKeysTrustValidatorImpl class. The ECDSA signature verification process discards the boolean return value of the Signature.verify() function. Although the system performs certificate chain validation, OCSP checks, and signature algorithm setup, it fails to verify if the signature actually matches, resulting in the function returning true for any structurally valid signature.Recommendations
Update to the version that includes the fix provided in pull request #34.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Epa4All-Client