PT-2026-69884 · Jaspersoft · Jasperreports Server

CVE-2026-16626

·

Published

2026-08-10

·

Updated

2026-08-11

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L
Name of the Vulnerable Software and Affected Versions Jaspersoft JasperReports Server versions 9.0.0 through 9.0.0 before HF-9 Jaspersoft JasperReports Server versions 10.0.0 through 10.0.0 before HF-10
Description An unauthenticated user can exploit an improper restriction of XML external entity (XXE) references. XXE is a type of attack where an application processes XML input containing a reference to an external entity, potentially allowing the attacker to read local files or interact with internal systems.
Recommendations Update Jaspersoft JasperReports Server version 9.0.0 to HF-9 or later. Update Jaspersoft JasperReports Server version 10.0.0 to HF-10 or later.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16626

Affected Products

Jasperreports Server