CVE-2026-16999 PUBLISHED

XXE in Ministry of Justice's UYAP Document Editor

Assigner: TR-CERT
Reserved: 24.07.2026 Published: 12.08.2026 Updated: 12.08.2026

Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking.

This issue affects UYAP Document Editor: from 4.5.17 before 5.4.17.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
CVSS Score: 6.3

Product Status

Vendor Ministry of Justice
Product UYAP Document Editor
Versions Default: unaffected
  • affected from 4.5.17 to 5.4.17 (excl.)

Credits

  • Mustafa Anıl YILDIRIM finder
  • Begüm ERDAL finder

References

Problem Types

  • CWE-611 Improper restriction of XML external entity reference CWE

Impacts

  • CAPEC-201 Serialized Data External Linking