Critical security vulnerabilities in Belgium’s national eID middleware exposed users across eight of the country’s ten largest banks and more than 60 government agencies to remote code execution and identity theft attacks according to SecurityWeek. No CVE identifiers have been published and no Belgian government advisory from CERT.be or the Centre for Cybersecurity Belgium appears in the public record at time of writing which makes independent verification of scope and severity harder than it should be for a disclosure of this scale.
The middleware in question handles authentication between Belgian eID smart cards and third-party services. Because the eID card is the primary digital identity credential for Belgian citizens, a remote code execution flaw in that layer is not a theoretical risk. An attacker who could reach the affected endpoint during an authentication session had a potential path to both credential theft and arbitrary code execution on the user’s machine.
Open-Sourcing Is a Fix for the Future, Not the Past
The Belgian federal government has open-sourced the eID middleware, now available on GitHub under the Fedict organisation. The move is the right one. Code that handles national identity authentication should be open to public audit and the vulnerabilities found here are a direct argument for why closed-source identity infrastructure carries hidden systemic risk. But open-sourcing resolves the transparency problem going forward. It does not retroactively explain how long the flaws existed, how they were discovered or whether they were exploited before the fix was issued.
Those are questions the Centre for Cybersecurity Belgium has not yet answered publicly. That silence is its own problem.
If You Use Belgian eID Services, Act Now
Update the eID middleware to the latest version available via the official Belgian government portal or the Fedict GitHub repository. If your organisation integrates eID authentication into a customer-facing service, verify with your vendor or development team that the patched version is deployed. No named patch version has been confirmed in available public sources so check the GitHub release log directly.
Organisations that rely on eID-based login for access to financial or government platforms should review their authentication logs for anomalous session activity during the period before the patch was released. The window of exposure is unknown.
References
- Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
- Fedict eID Middleware on GitHub
- Belgian eID Middleware Open-Sourced
This post is also available in: