Intel

AIKIDO-2026-11136

jasperreports is vulnerable to Deserialization of Untrusted Data

Deserialization of Untrusted DataCVE-2026-6009 Published 2 days ago

87

High Risk

This Affects:

JAVAjasperreports
1.0.0 - 7.0.6
Fixed in 7.0.7
Are you affected? Scan for Free

TL;DR

A Java deserialisation vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

jasperreports is vulnerable to Deserialization of Untrusted Data in versions 1.0.0 - 7.0.6.

How to fix this

Upgrade the net.sf.jasperreports:jasperreports library to a patch version.