Improper XML External Entity Management in Jaspersoft JasperReports Server
CVE-2026-16626

9.3CRITICAL

Key Information:

Vendor

Jaspersoft

Vendor
CVE Published:
10 August 2026

What is CVE-2026-16626?

The vulnerability in Jaspersoft JasperReports Server arises from improper handling of XML external entity (XXE) references. This can allow unauthenticated users to access sensitive data and potentially execute malicious XML content. Affected versions prior to HF-9 on 9.0.0 and HF-10 on 10.0.0 are susceptible to this flaw, emphasizing the need for timely updates to secure the application against exploitation.

Affected Version(s)

JasperReports Server 9.0.0

JasperReports Server 10.0.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.