CVE-2026-33874

Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior to version 4.16.0, the Mac OS version of the Authenticator is vulnerable to remote code execution, triggered when victims open a malicious file. Update the gematik Authenticator to version 4.16.0 or greater to receive a patch. There are no known workarounds.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:gematik:authenticator:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

01 Apr 2026, 13:42

Type Values Removed Values Added
First Time Gematik
Apple macos
Apple
Gematik authenticator
CPE cpe:2.3:a:gematik:authenticator:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
References () https://github.com/gematik/app-Authenticator/security/advisories/GHSA-mjgm-7hwc-qqcr - () https://github.com/gematik/app-Authenticator/security/advisories/GHSA-mjgm-7hwc-qqcr - Vendor Advisory

27 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-27 21:17

Updated : 2026-04-01 13:42


NVD link : CVE-2026-33874

Mitre link : CVE-2026-33874

CVE.ORG link : CVE-2026-33874


JSON object : View

Products Affected

gematik

  • authenticator

apple

  • macos
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')