PatchSiren cyber security CVE debrief
CVE-2026-16999 Ministry of Justice CVE debrief
The Ministry of Justice UYAP Document Editor is vulnerable to an improper restriction of XML external entity reference, allowing Serialized Data External Linking. This issue affects versions from 4.5.17 before 5.4.17. The vulnerability has a CVSS score of 6.3 and a severity of MEDIUM. Administrators and users of UYAP Document Editor versions 4.5.17 to 5.4.17 should review and apply patches or updates to mitigate potential risks. The CVE record was published on 2026-08-12T14:17:47.890Z and has not been modified since then.
- Vendor
- Ministry of Justice
- Product
- UYAP Document Editor
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-12
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-12
- Advisory updated
- 2026-08-26
Who should care
Administrators and users of UYAP Document Editor versions 4.5.17 to 5.4.17 should review and apply patches or updates to mitigate potential risks. The vulnerability has a medium-priority defensive review recommended due to potential for localized impact. Users of UYAP Document Editor should also implement compensating controls such as input validation and XML parsing restrictions, and monitor for suspicious activity and exception tracking.
Technical summary
The Ministry of Justice UYAP Document Editor is vulnerable to an improper restriction of XML external entity reference, allowing Serialized Data External Linking. This issue affects versions from 4.5.17 before 5.4.17. The vulnerability has a CVSS score of 6.3 and a severity of MEDIUM. The affected product is UYAP Document Editor, and the vulnerability has a medium-priority defensive review recommended due to potential for localized impact.
Defensive priority
Medium-priority defensive review recommended due to potential for localized impact.
Recommended defensive actions
- Review and apply vendor-provided patches or updates for UYAP Document Editor.
- Implement compensating controls such as input validation and XML parsing restrictions.
- Monitor for suspicious activity and exception tracking.
Evidence notes
Evidence from official CVE and NVD sources indicates an improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor, allowing Serialized Data External Linking. Affected versions are from 4.5.17 before 5.4.17.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-16999 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-16999
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-16999 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16999
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0818
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.