Gematik develops authentication and validation infrastructure for Germany's healthcare system, with its vulnerability profile concentrated in products such as the Authenticator and Reference Validator. The recurring exposure centers on input-handling and external-entity parsing weaknesses including OS command injection and improper XML external-entity handling, reflecting the attack surface inherent to server-side validation and authentication gateways. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gematik over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33875CRITICAL Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially a | Mar 27, 2026 | 9.3 | 32 | NO | NO |
CVE-2024-46984CRITICAL The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperability standards. The profile location routine in the reference | Sep 19, 2024 | 9.8 | 27 | NO | NO |
CVE-2026-33874HIGH Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior to version 4.16.0, the Mac OS version of the Authe | Mar 27, 2026 | 7.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gematik.
Media articles that mention a CVE ID that affects a product developed by Gematik — matched by CVE ID, not by vendor name.