Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-16626: JasperReports Server: Unrestricted Access to External Data
CVE-2026-16626 · published 1 month ago
Summary
JasperReports Server, used for generating reports, has a security flaw that allows attackers to access external data without needing a login. This affects versions 9.0.0 and later until a specific update is applied, and versions 10.0.0 until a specific update is applied. It's essential to update your JasperReports Server to the latest version to prevent unauthorized access.
What to do
- Update jaspersoft jasperreports server to version HF-9 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jaspersoft | jasperreports server | < HF-9 |
Original advisory text
JasperReports Server: XXE Injection Vulnerability (Unauthenticated)
Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server.
This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.0.0 before HF-10.
This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.0.0 before HF-10.
Severity
9.3
Critical
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-611XML External Entity (XXE)
Timeline
Published10 Aug 2026
Updated27 Sep 2026
First seen10 Aug 2026
Track software like this
Free during beta