Sceawere

Vulnerability Detail

CVE-2026-16999UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

UYAP Document Editor XXE Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
2h ago
Vendor
Ministry of Justice
Product
UYAP Document Editor
Attack Type
CWE-611 Improper restriction of XML external entity reference
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking. This issue affects UYAP Document Editor: from 4.5.17 before 5.4.17.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-08-12T14:17:47.890Z",
  "pubdate": "2026-08-12T14:17:47.890Z",
  "executiveSummary": "An improper restriction of XML external entity reference vulnerability exists within the Ministry of Justice UYAP Document Editor, specifically enabling Serialized Data External Linking. This security flaw permits an unauthenticated remote attacker to construct malicious XML payloads that leverage external entity resolution mechanisms within the document parsing engine. When a vulnerable instance of the UYAP Document Editor processes a crafted document containing malicious XML external entity references or serialized data links, the application evaluates these references improperly, exposing the underlying host system to substantial risk. The primary impact includes potential arbitrary data disclosure, server-side request forgery, or secondary exploitation vectors inherent to insecure XML parsing configurations. The vulnerability specifically affects UYAP Document Editor versions ranging from 4.5.17 prior to the patched version 5.4.17. Successful exploitation generally requires user interaction in the form of opening a maliciously crafted document file within the editor. Remediation requires updating the affected software to version 5.4.17 or later where the XML parser restrictions are properly enforced.",
  "technicalDetails": "The vulnerability stems from an improper restriction of XML external entity references within the XML parser configuration utilized by the UYAP Document Editor. Specifically, the application processes XML-based document structures without disabling Document Type Definition (DTD) processing and external entity resolution. When the vulnerable parser encounters XML input containing custom entity definitions referencing external resources, it attempts to resolve and load the specified URIs or serialized data links.\nThe attack flow proceeds as follows: First, an attacker crafts a malicious document file formatted in XML that includes external entity declarations pointing to internal files, local network resources, or external malicious endpoints. Second, the victim opens the crafted document using a vulnerable version of the UYAP Document Editor (from 4.5.17 before 5.4.17). Third, the internal XML parser component parses the document and resolves the malicious external entities. Finally, depending on the nature of the external reference, the parser either discloses local file contents back to the attacker, interacts with internal network services via Server-Side Request Forgery, or facilitates Serialized Data External Linking behaviors.\nThe root cause is the lack of explicit hardening of the XML parsing engine, specifically failing to set properties such as disallowing DTDs and disabling external general entities and external parameter entities. The vulnerable component is the document parsing module responsible for ingesting and rendering XML-based document formats within the UYAP Document Editor. Exploitation does not require prior authentication or privileged access within the application, but it relies on victim interaction to open the malicious file."
}
CVE-2026-16999: UYAP Document Editor XXE Vulnerability (MEDIUM Severity, CVSS: 6.3) - Sceawere