Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-16626: JasperReports Server: Unrestricted Access to External Data

CVE-2026-16626 · published 1 month ago
Summary

JasperReports Server, used for generating reports, has a security flaw that allows attackers to access external data without needing a login. This affects versions 9.0.0 and later until a specific update is applied, and versions 10.0.0 until a specific update is applied. It's essential to update your JasperReports Server to the latest version to prevent unauthorized access.

What to do
  • Update jaspersoft jasperreports server to version HF-9 or later.
Affected software
VendorProductAffected versions
jaspersoft jasperreports server < HF-9
Original advisory text
JasperReports Server: XXE Injection Vulnerability (Unauthenticated)
Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server.

This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.0.0 before HF-10.
Severity
9.3 Critical
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-611XML External Entity (XXE)
Timeline
Published10 Aug 2026
Updated27 Sep 2026
First seen10 Aug 2026
Sources
CVE-2026-16626 · MITRE
Track software like this
Free during beta