🔐 CVE Alert

CVE-2026-16999

MEDIUM 6.3

XXE in Ministry of Justice's UYAP Document Editor

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking. This issue affects UYAP Document Editor: from 4.5.17 before 5.4.17.

CWE CWE-611
Vendor ministry of justice
Product uyap document editor
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for ministry of justice uyap document editor

Be the first to know when new medium vulnerabilities affecting ministry of justice uyap document editor are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Ministry of Justice / UYAP Document Editor
4.5.17 < 5.4.17

References

NVD ↗ CVE.org ↗ EPSS Data ↗
siberguvenlik.gov.tr: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0818

Credits

Mustafa Anıl YILDIRIM Begüm ERDAL