AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16626

CRITICAL · CVSS 9.3 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

An improper restriction of XML external entity (XXE) vulnerability in Jaspersoft JasperReports Server allows unauthenticated attackers to exploit XML processing features, potentially leading to sensitive data exposure or server-side request forgery. Organizations using affected versions (9.0.0 before HF-9 and 10.0.0 before HF-10) should prioritize patching this critical vulnerability to mitigate the risk of data breaches and unauthorized access.

CVE
CVE-2026-16626
Severity
CRITICAL
CVSS
9.3
EPSS
0.33%

Original NVD Description

Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.0.0 before HF-10.