CVE-2026-16626: JasperReports Server: XXE Injection Vulnerability (Unauthenticated)
Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server.
This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.0.0 before HF-10.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jaspersoft JasperReports Serverto a version that resolves this vulnerability.Patch HF-9 - Upgrade
Upgrade
Jaspersoft JasperReports Serverto a version that resolves this vulnerability.Patch HF-10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16626?
The severity of CVE-2026-16626 is rated at 62.
How do I fix CVE-2026-16626?
To fix CVE-2026-16626, upgrade to JasperReports Server version 9.0.0 after HF-9 or 10.0.0 after HF-10.
What products are affected by CVE-2026-16626?
CVE-2026-16626 affects TIBCO JasperReports Server versions prior to specified hotfixes.
Is authentication required to exploit CVE-2026-16626?
Exploitation of CVE-2026-16626 does not require authentication.
What type of vulnerability is CVE-2026-16626?
CVE-2026-16626 is categorized as an XML External Entity (XXE) injection vulnerability.