PatchSiren cyber security CVE debrief
CVE-2026-16626 Jaspersoft CVE debrief
CVE-2026-16626 is an improper restriction of XML external entity reference vulnerability in Jaspersoft JasperReports Server, affecting versions from 9.0.0 before HF-9 and from 10.0.0 before HF-10. This critical vulnerability, with a CVSS score of 9.3, could allow unauthenticated attackers to exploit the server. Organizations using these versions should be aware of the potential risks and take immediate action to patch or mitigate the vulnerability. The CVE record was published on 2026-08-10T18:17:41.667Z and has not been modified since then. To address this vulnerability, defenders should review the official advisory, assess their exposure, and apply patches or compensating controls as necessary.
- Vendor
- Jaspersoft
- Product
- JasperReports Server
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-08-31
Who should care
Organizations using Jaspersoft JasperReports Server, especially those using versions from 9.0.0 before HF-9 and from 10.0.0 before HF-10, should be aware of this critical vulnerability and take immediate action to patch or mitigate. This includes reviewing their current deployments, assessing potential exposure, and implementing compensating controls if necessary. IT operators, security teams, and vulnerability management teams should prioritize this issue and coordinate with vendors for patches or updates.
Technical summary
CVE-2026-16626 is an improper restriction of XML external entity reference vulnerability in Jaspersoft JasperReports Server. The vulnerability affects versions from 9.0.0 before HF-9 and from 10.0.0 before HF-10, with a CVSS score of 9.3 indicating critical severity. This type of vulnerability could allow attackers to exploit the server through XXE attacks. To mitigate this risk, defenders should apply patches, review and update their inventory, and implement compensating controls.
Defensive priority
Organizations using Jaspersoft JasperReports Server versions from 9.0.0 before HF-9 and from 10.0.0 before HF-10 should prioritize patching to prevent potential XXE attacks.
Recommended defensive actions
- Apply patches for Jaspersoft JasperReports Server versions from 9.0.0 before HF-9 and from 10.0.0 before HF-10
- Review and update inventory to identify and prioritize affected systems
- Implement compensating controls to detect and prevent XXE attacks
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE-2026-16626 record indicates an improper restriction of XML external entity reference vulnerability in Jaspersoft JasperReports Server. Affected versions include 9.0.0 before HF-9 and 10.0.0 before HF-10. The CVSS score is 9.3, indicating critical severity. The evidence is based on the official CVE Program record and the NIST NVD detail page. Defenders should verify the affected scope, review compensating controls, and monitor for potential attacks. The information provided is based on the available data and may not be exhaustive.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-16626 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-16626
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-16626 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16626
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://community.jaspersoft.com/advisories/jaspersoft-security-advisory-august-05-2026-jasperreports-server-cve-2026-16626-r12/
db6d2600-d19b-4111-a010-f3c4ed70cd50
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.