CVE-2026-16999: XXE in Ministry of Justice's UYAP Document Editor
Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking.
This issue affects UYAP Document Editor: from 4.5.17 before 5.4.17.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ministry of Justice UYAP Document Editorto a version that resolves this vulnerability.Fixed in 5.4.17
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16999?
The severity of CVE-2026-16999 is classified as medium with a score of 6.3.
How do I fix CVE-2026-16999?
To mitigate CVE-2026-16999, upgrade the UYAP Document Editor to version 5.4.17 or later.
Which versions of UYAP Document Editor are affected by CVE-2026-16999?
CVE-2026-16999 affects UYAP Document Editor versions from 4.5.17 before 5.4.17.
What type of vulnerability is CVE-2026-16999?
CVE-2026-16999 is an improper restriction of XML external entity reference vulnerability.
What impact does CVE-2026-16999 have on systems?
CVE-2026-16999 allows Serialized Data External Linking which can lead to data exposure.