What is CVE-2026-16999?
CVE-2026-16999 is an XML External Entity (XXE) vulnerability in the Ministry of Justice's UYAP Document Editor, caused by improper restriction of XML external entity references. This flaw allows Serialized Data External Linking, potentially leading to sensitive data exposure. Affected versions are from 4.5.17 before 5.4.17, requiring an immediate update to version 5.4.17 or later.
Azərbaycanca: CVE-2026-16999, Ədliyyə Nazirliyinin UYAP Sənəd Redaktorunda XML xarici obyekt (XXE) zəifliyidir. Bu zəiflik Serialized Data External Linking vasitəsilə məxfi məlumatların sızmasına səbəb ola bilər. UYAP Sənəd Redaktorunun 4.5.17-dən 5.4.17-yə qədər olan versiyaları təsirlənir, dərhal 5.4.17 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-611
FAQ2
Which versions of the UYAP Document Editor are affected by the CVE-2026-16999 vulnerability?
This XML External Entity (XXE) vulnerability affects UYAP Document Editor versions from 4.5.17 before 5.4.17.
What is the primary risk posed by CVE-2026-16999?
This flaw allows Serialized Data External Linking, potentially leading to sensitive data exposure.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.