CVE-2026-16999EPSS p2.9%
CVE-2026-16999CVE-2026-16999
Description
Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking.
This issue affects UYAP Document Editor: from 4.5.17 before 5.4.17.
Scoring
| CVSS | 6.3 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N |
| EPSS | 0.13% probability of exploitation · percentile 2.9% · 2026-08-13T12:03:51Z |
| Last modified | 2026-08-12 |