CVE-2026-33875 is a critical authentication flow hijacking vulnerability (CVSS 9.3) affecting Gematik Authenticator versions prior to 4.16.0. This flaw allows an attacker to authenticate with a victim's identity if the victim clicks a malicious deep link, leading to high confidentiality and integrity impacts. The attack is network-based with low complexity but requires user interaction. There are no known workarounds, necessitating an update to version 4.16.0 or greater. While not actively exploited or having public exploit code, the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.16.0CPE matchmatch criteria | cpe:2.3:a:gematik:authenticator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.