PT-2026-69884 · Jaspersoft · Jasperreports Server
CVE-2026-16626
·
Published
2026-08-10
·
Updated
2026-08-11
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
Jaspersoft JasperReports Server versions 9.0.0 through 9.0.0 before HF-9
Jaspersoft JasperReports Server versions 10.0.0 through 10.0.0 before HF-10
Description
An unauthenticated user can exploit an improper restriction of XML external entity (XXE) references. XXE is a type of attack where an application processes XML input containing a reference to an external entity, potentially allowing the attacker to read local files or interact with internal systems.
Recommendations
Update Jaspersoft JasperReports Server version 9.0.0 to HF-9 or later.
Update Jaspersoft JasperReports Server version 10.0.0 to HF-10 or later.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jasperreports Server