Junglewise Threat Intelligence

CVE-2026-6009: Jaspersoft Reports Library Java deserialization RCE

CVE-2026-6009 · Severity: high · CVSS 4 · Published 2026-05-19

Vendors: Maven.

Executive brief

Jaspersoft Reports, a widely used Java reporting library, is vulnerable to a security flaw that could allow an attacker to take control of the server. By sending specially crafted data, an attacker with low-level access can execute unauthorized commands on the system. This could lead to the theft of sensitive business data, service disruptions, or full system compromise.

Technical details

A Java Deserialization vulnerability (CWE-502) exists in the Jaspersoft Reports Library (net.sf.jasperreports:jasperreports) in versions prior to 7.0.7. The flaw occurs when the library processes untrusted serialized data, allowing an attacker to trigger remote code execution (RCE). Exploitation requires network access and low-level privileges (PR:L) but no user interaction. Successful exploitation grants the attacker high impact over confidentiality, integrity, and availability of the affected system. The issue is resolved in version 7.0.7.

Affected products

  • Jaspersoft JasperReports Library < 7.0.7

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: advisory
  • 2026-07-10: patched: Advisory updated with patch information

References

Related threats