CVE-2026-16626
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L
Summary
Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server.
This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.0.0 before HF-10.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Jaspersoft | JasperReports Server | 9.0.0 < HF-9 | affected |
| Jaspersoft | JasperReports Server | 10.0.0 < HF-10 | affected |
Weaknesses
- CWE-611: CWE-611 Improper restriction of XML external entity reference
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.