What is CVE-2026-16027?
CVE-2026-16027 is a Server-Side Request Forgery (SSRF) vulnerability found in Revenue Administration Türkiye's E-Signature application. This flaw allows an attacker to send crafted requests from the server to unauthenticated sources. Affected versions range from 2.4.4.0 to before 2.5.1.0, and immediate update to version 2.5.1.0 or newer is recommended.
Azərbaycanca: CVE-2026-16027 Türkiyə Gəlir İdarəsinin E-İmza tətbiqində aşkarlanmış Server-Side Request Forgery (SSRF) zəifliyidir. Bu boşluq təsdiqlənməmiş mənbələrdən serverə saxta sorğular göndərməyə imkan verir. 2.4.4.0 - 2.5.1.0 versiyaları arası təsirlənir, dərhal 2.5.1.0 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which application is affected by CVE-2026-16027?
CVE-2026-16027 affects the E-Signature application of Revenue Administration Türkiye.
Which version should be updated to in order to fix CVE-2026-16027?
To fix CVE-2026-16027, immediate update to version 2.5.1.0 or newer is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.