AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16999

MEDIUM · CVSS 6.3 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The UYAP Document Editor versions prior to 5.4.17 are vulnerable to an improper restriction of XML external entity references, which could allow attackers to exploit serialized data external linking. This vulnerability poses a medium risk, potentially leading to unauthorized data access or manipulation. Organizations utilizing the affected versions of the UYAP Document Editor should prioritize patching to mitigate potential security risks.

CVE
CVE-2026-16999
Severity
MEDIUM
CVSS
6.3
EPSS
0.13%

Original NVD Description

Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking. This issue affects UYAP Document Editor: from 4.5.17 before 5.4.17.