CVE-2026-16626
9.3Jaspersoft · JasperReports Server
An unauthenticated XML external entity (XXE) vulnerability in Jaspersoft JasperReports Server allows remote attackers to read sensitive files or potentially cause a denial of service.
Executive summary
This critical vulnerability in Jaspersoft JasperReports Server allows unauthenticated remote attackers to perform unauthorized file access, posing a severe risk to data confidentiality.
Vulnerability
This is an improper restriction of XML external entity reference (CWE-611) vulnerability. It allows an unauthenticated attacker to supply malicious XML input that the server parses, leading to unauthorized disclosure of local system files.
Business impact
The vulnerability carries a CVSS score of 9.3, classifying it as critical. Successful exploitation could lead to full exposure of sensitive configuration files, credentials, or system data, resulting in significant data breaches and potential compromise of the underlying infrastructure.
Remediation
Immediate Action: Upgrade to the patched versions (HF-9 for 9.0.0 or HF-10 for 10.0.0) as provided by the vendor.
Proactive Monitoring: Monitor server logs for unusual XML parsing activity or attempts to access restricted file paths via GET or POST requests.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block malicious XML payloads and DTD (Document Type Definition) injections.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the critical CVSS severity and the ease of exploitation by unauthenticated actors, organizations must prioritize patching these JasperReports Server instances immediately. Ensure that all affected nodes are identified and updated to the specified hotfix levels to prevent unauthorized data access.