CVE-2026-33875Disclosure(gematik / authenticator)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gematik authenticator systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing attackers to authenticate with the identities of victim users who click on a malicious deep link. Update Gematik Authenticator to version 4.16.0 or greater to receive a patch. There are no known workarounds.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-940

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • authenticator

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-27); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
authenticator

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-27: 3Mentions · 2026-03-28: 1Mentions · 2026-03-29: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-27: 3Technical Details · 2026-03-28: 1Technical Details · 2026-03-29: 103-2703-2803-29
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-273
Disclosure2Patch1
2026-03-281
Disclosure1
2026-03-291
Disclosure1
Full discourse5 posts
  • CosmicBytez@CosmicBytez
    Disclosure

    Security Advisory: CVE-2026-33875 — Gematik Authenticator Authentication Flow Hijacking (CVSS 9.3) https://labs.cosmicbytez.ca/security/cve-2026-33875 #Cybersecurity #InfoSec #CVE #PatchNow

    Post summary

    The advisory announces CVE-2026-33875 as an authentication flow hijacking vulnerability in Gematik Authenticator with a high CVSS score, but it does not provide PoC, exploit code, active exploitation evidence, or patch details.

    0000022
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33875 Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking,… https://www.cve.org/CVERecord?id=CVE-2026-33875

    Post summary

    CVE‑2026‑33875 is disclosed, indicating that Gematik Authenticator versions prior to 4.16.0 are vulnerable to authentication flow hijacking, with no PoC, exploit, or patch details provided.

    00000117
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33875 - Critical Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing... https://www.thehackerwire.com/vulnerability/CVE-2026-33875/ https://t.co/SflLmdvjiB

    Post summary

    The tweet announces CVE‑2026‑33875 as a critical authentication flow hijacking vulnerability in Gematik Authenticator versions below 4.16.0, providing basic technical details but lacking any PoC, exploit, active exploitation claim, or patch information.

    0000049
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33875: CRITICAL] Update Gematik Authenticator to version 4.16.0 to fix vulnerability allowing authentication flow hijacking. Protect your digital health applications from potential cyber attacks.#cve,CVE-2026-33875,#cybersecurity https://cvefind.com/CVE-2026-33875

    Post summary

    The advisory recommends updating to Gematik Authenticator 4.16.0 to patch a critical authentication flow hijacking vulnerability. No PoC, exploit code, or active exploitation evidence is mentioned.

    0000037
    617 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33875: Authenticator Vulnerable to Auth... Deep link hijacking healthcare auth with 9.3 CVSS - one malicious URL click = full identity takeover in German health e... https://zerodaysignal.com/vulnerability/CVE-2026-33875 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-33875, a 9.3‑scored vulnerability in a healthcare authenticator that allows full identity takeover via a single malicious deep link, with no PoC, tool, patch, or active exploitation reported.

    0000061
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgematikauthenticator---

Explore more