Description
Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking.

This issue affects UYAP Document Editor: from 4.5.17 before 5.4.17.
Published: 2026-08-12
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The identified vulnerability is an improper restriction of XML external entity references in the ministry’s UYAP Document Editor. This flaw allows an attacker to embed serialized data external links within an XML document, potentially enabling the reading of arbitrary local files or the execution of remote code if the editor processes such entities. Consequently, confidential information could be exfiltrated, and in certain configurations may lead to further exploitation such as remote code execution.

Affected Systems

The Ministry of Justice’s UYAP Document Editor versions 4.5.17 through the release just prior to 5.4.17 are affected. This includes all builds from 4.5.17 up to 5.4.16 (inclusive).

Risk and Exploitability

The CVSS score of 6.3 classifies the vulnerability as medium severity, suggesting noticeable risk without immediate guarantee of exploitation. Exploitability requires an attacker to submit a maliciously crafted XML document via the document editor interface, meaning network exposure of or legitimate use of the editor is a prerequisite. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on August 13, 2026 at 00:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade UYAP Document Editor to version 5.4.17 or later, which resolves the XML External Entity handling issue.
  • If an upgrade is not immediately possible, configure the underlying XML parser to disable external entity processing or use restricted parser settings to prevent DTD processing.
  • Ensure the editor is accessed only over secure, authenticated channels and restrict file uploads to trusted users to limit potential misuse of the vulnerability.

Generated by OpenCVE AI on August 13, 2026 at 00:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Ministry Of Justice
Ministry Of Justice uyap Document Editor
Vendors & Products Ministry Of Justice
Ministry Of Justice uyap Document Editor

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking. This issue affects UYAP Document Editor: from 4.5.17 before 5.4.17.
Title XXE in Ministry of Justice's UYAP Document Editor
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}


Subscriptions

Ministry Of Justice Uyap Document Editor
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-12T18:47:18.379Z

Reserved: 2026-07-24T09:22:51.337Z

Link: CVE-2026-16999

cve-icon Vulnrichment

Updated: 2026-08-12T18:47:14.835Z

cve-icon NVD

Status : Deferred

Published: 2026-08-12T14:17:47.890

Modified: 2026-08-26T16:51:19.490

Link: CVE-2026-16999

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:48:42Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference