External risk intelligence

JasperReports Server XML External Entity Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-16626

JasperReports Server is typically deployed as a web-based reporting and analytics application, often accessible to users over the network or via an integrated web portal. Because it serves as a central reporting interface for users, it is frequently configured to be reachable as an internet-facing or intranet-facing web application.

XML External Entity Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Jaspersoft JasperReports Server could allow unauthenticated attackers to access or manipulate data through improper handling of external data references. This issue affects specific versions of JasperReports Server and warrants attention to confirm if your environment is exposed.

  • XML external data reference vulnerability.
  • Unauthenticated access to JasperReports Server.
  • Confirm exposure and business relevance.

Attack Path

How an attacker could exploit the issue

Attackers can exploit an improperly restricted XML external entity reference in JasperReports Server. This vulnerability allows unauthenticated access, meaning an attacker does not need a username or password to initiate the attack. By sending a specially crafted XML input, an attacker can potentially manipulate the server to process malicious external entities, leading to severe consequences.

  • No authentication required.
  • Malicious XML input triggers vulnerability.
  • Leads to critical information disclosure.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated vulnerability in JasperReports Server could allow an attacker to access sensitive information by exploiting improperly restricted external entity references in XML. This could affect system data and potentially sensitive information when the JasperReports Server is accessible over a network.

  • System data and sensitive information.
  • XML parsing with external entities.
  • Information disclosure and system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in JasperReports Server likely impacts application owners and infrastructure teams responsible for its deployment and maintenance. The first practical step is to identify all instances of JasperReports Server, confirm their network exposure and business criticality, and then assign an accountable owner for remediation planning.

  • Application owners should prioritize this issue.
  • Verify all JasperReports Server instances.
  • Plan remediation based on exposure and criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Jaspersoft JasperReports Server?

JasperReports Server is a web-based reporting and analytics platform used by organizations to create, manage, and distribute data visualizations and business reports. It functions as a central hub where users can access interactive dashboards and scheduled report outputs. Because it integrates with various data sources, it often sits as a critical middle tier in enterprise software environments, processing complex data structures to deliver insights to end users.

How does CVE-2026-16626 work?

This vulnerability is an Improper Restriction of XML External Entity Reference (CWE-611). It occurs when the server processes XML input without properly validating or limiting external references. An attacker can supply a malicious XML document that forces the server to interact with unintended external resources, potentially leading to unauthorized data disclosure or system manipulation.

Do I need to be logged in to trigger this bug?

No, this vulnerability is unauthenticated. This means an attacker does not require valid credentials or a user account to send the malicious XML input to the server. The flaw is triggered through the way the application processes incoming requests, meaning standard user access controls do not prevent the initial malicious interaction.

Is my JasperReports Server at risk?

According to Halo Surface Signal, JasperReports Server is typically deployed as a web application reachable over a network or via integrated portals. If your instance is configured to be internet-facing or accessible to a broad internal network, it is at higher risk. You should evaluate the network reachability of your server to determine if it is exposed to unauthorized entities.

How should I respond to this threat advisory?

Begin by auditing your environment to locate all instances of JasperReports Server. Once identified, confirm the specific version you are running against those listed as affected. Prioritize these instances based on their network connectivity and the sensitivity of the data they handle, and coordinate with your infrastructure team to plan the deployment of the necessary software updates.

References