Description
Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing attackers to authenticate with the identities of victim users who click on a malicious deep link. Update Gematik Authenticator to version 4.16.0 or greater to receive a patch. There are no known workarounds.
CVSS Metrics
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
- Attack Vector
- network
- Complexity
- low
- Privileges
- none
- User Action
- required
- Scope
- changed
- Confidentiality
- high
- Integrity
- high
- Availability
- none
- Weaknesses
- CWE-940
Metadata
- Primary Vendor
- GEMATIK
- Published
- 3/27/2026
- Last Modified
- 4/3/2026
- Source
- NIST NVD
- Note: Verify all details with official vendor sources before applying patches.
Affected Products
gematik : authenticator
AI-Powered Remediation
Generate remediation guidance or a C-suite brief for this vulnerability.