CVE-2026-47672: epa4all-client: Unauthenticated REST API for Patient Record Writes
Any network-reachable caller can write arbitrary documents to any patient’s electronic health record accessible by the institution’s SMC-B card. In a misconfigured deployment (e.g., following the production Docker example in the README), this is exploitable from the local network without credentials.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-47672 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →