CVE-2026-16626
Received Received - Intake

Unauthenticated XXE in JasperReports Server

Vulnerability report for CVE-2026-16626, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: Jaspersoft

Description

Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.0.0 before HF-10.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
jaspersoft jasperreports_server From 9.0.0 (inc) to 9.0.0 (exc)
jaspersoft jasperreports_server From 10.0.0 (inc) to 10.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-611 The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an improper restriction of XML external entity reference vulnerability in Jaspersoft JasperReports Server. It allows unauthenticated attackers to exploit XML parsing flaws to read files, execute remote requests, or perform denial of service attacks.

Detection Guidance

Detecting this XXE vulnerability requires checking for exposed JasperReports Server instances and testing for XML external entity processing. Scan your network for servers running JasperReports Server versions 9.0.0 before HF-9 or 10.0.0 before HF-10. Use tools like Nmap to identify open ports and services. Test for XXE by sending crafted XML payloads to the server's endpoints, such as report generation or data import features.

Impact Analysis

An attacker could exploit this to access sensitive files, perform server-side request forgery, or crash the server. Systems running affected versions without patches are at high risk of compromise.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating GDPR (data protection) and HIPAA (health data privacy). Organizations must patch systems to maintain compliance and avoid legal penalties.

Mitigation Strategies

Immediately upgrade JasperReports Server to versions HF-9 or later for 9.x and HF-10 or later for 10.x. Disable XML external entity processing in the server's XML parser configuration. Restrict network access to the server by blocking unnecessary ports. Monitor for suspicious activity and apply patches as soon as possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16626. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart