CVE-2026-16027: Unauthenticated WebSocket-to-XAdES SSRF in Revenue Administration of Türkiye's E-Signature
Published Aug 7, 2026
·Updated
Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery.
This issue affects Türkiye's E-Signature: from 2.4.4.0 before 2.5.1.0.
Affected Software
1 affected component
E-Signature (Türkiye)>2.4.4.0<2.5.1.0
Event History
Aug 7, 2026
CVE Published
via MITRE·07:14 AM
Data Sourced
via MITRE·07:14 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-16027?
CVE-2026-16027 has a medium severity score of 5.4.
2
How do I fix CVE-2026-16027?
To fix CVE-2026-16027, upgrade Türkiye's E-Signature software from versions prior to 2.5.1.0.
3
What type of vulnerability is CVE-2026-16027?
CVE-2026-16027 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
4
Which versions of Türkiye's E-Signature are affected by CVE-2026-16027?
CVE-2026-16027 affects Türkiye's E-Signature software versions from 2.4.4.0 to before 2.5.1.0.
5
What impact does CVE-2026-16027 have on security?
The impact of CVE-2026-16027 allows unauthorized server-side requests, potentially compromising system security.