PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16626 Jaspersoft CVE debrief

CVE-2026-16626 is an improper restriction of XML external entity reference vulnerability in Jaspersoft JasperReports Server, affecting versions from 9.0.0 before HF-9 and from 10.0.0 before HF-10. This critical vulnerability, with a CVSS score of 9.3, could allow unauthenticated attackers to exploit the server. Organizations using these versions should be aware of the potential risks and take immediate action to patch or mitigate the vulnerability. The CVE record was published on 2026-08-10T18:17:41.667Z and has not been modified since then. To address this vulnerability, defenders should review the official advisory, assess their exposure, and apply patches or compensating controls as necessary.

Vendor
Jaspersoft
Product
JasperReports Server
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-08-31
Advisory published
2026-08-10
Advisory updated
2026-08-31

Who should care

Organizations using Jaspersoft JasperReports Server, especially those using versions from 9.0.0 before HF-9 and from 10.0.0 before HF-10, should be aware of this critical vulnerability and take immediate action to patch or mitigate. This includes reviewing their current deployments, assessing potential exposure, and implementing compensating controls if necessary. IT operators, security teams, and vulnerability management teams should prioritize this issue and coordinate with vendors for patches or updates.

Technical summary

CVE-2026-16626 is an improper restriction of XML external entity reference vulnerability in Jaspersoft JasperReports Server. The vulnerability affects versions from 9.0.0 before HF-9 and from 10.0.0 before HF-10, with a CVSS score of 9.3 indicating critical severity. This type of vulnerability could allow attackers to exploit the server through XXE attacks. To mitigate this risk, defenders should apply patches, review and update their inventory, and implement compensating controls.

Defensive priority

Organizations using Jaspersoft JasperReports Server versions from 9.0.0 before HF-9 and from 10.0.0 before HF-10 should prioritize patching to prevent potential XXE attacks.

Recommended defensive actions

  • Apply patches for Jaspersoft JasperReports Server versions from 9.0.0 before HF-9 and from 10.0.0 before HF-10
  • Review and update inventory to identify and prioritize affected systems
  • Implement compensating controls to detect and prevent XXE attacks
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE-2026-16626 record indicates an improper restriction of XML external entity reference vulnerability in Jaspersoft JasperReports Server. Affected versions include 9.0.0 before HF-9 and 10.0.0 before HF-10. The CVSS score is 9.3, indicating critical severity. The evidence is based on the official CVE Program record and the NIST NVD detail page. Defenders should verify the affected scope, review compensating controls, and monitor for potential attacks. The information provided is based on the available data and may not be exhaustive.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-16626 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-16626

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-16626 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16626

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://community.jaspersoft.com/advisories/jaspersoft-security-advisory-august-05-2026-jasperreports-server-cve-2026-16626-r12/

    db6d2600-d19b-4111-a010-f3c4ed70cd50

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.