Junglewise Threat Intelligence

CVE-2026-16626: Jaspersoft JasperReports Server XXE in XML parsing

CVE-2026-16626 · Severity: info · Published 2026-08-10

Executive brief

JasperReports Server is a business intelligence and reporting platform used to generate and manage enterprise reports. An unauthenticated XML External Entity (XXE) vulnerability allows attackers to read arbitrary files from the server, retrieve sensitive data, or cause denial of service without requiring valid credentials or authentication.

Technical details

This is an XXE (XML External Entity) vulnerability in JasperReports Server's XML parsing functionality. The vulnerability allows unauthenticated attackers to submit malicious XML that references external entities, potentially enabling file disclosure, server-side request forgery (SSRF), or denial of service. The affected versions are 9.0.0 through before HF-9 and 10.0.0 through before HF-10. The network attack vector indicates the vulnerability is remotely exploitable without authentication. Patches are available as HF-9 for the 9.x branch and HF-10 for the 10.x branch.

Affected products

  • Jaspersoft JasperReports Server 9.0.0 to before 9.0.0-HF-9 and 10.0.0 to before 10.0.0-HF-10

Timeline

  • 2026-08-10: disclosed
  • 2026-08-05: patched: HF-9 for 9.x and HF-10 for 10.x releases

References