CVE Database
/

CVE-2026-6009

Back to search

CVE-2026-6009

Published: May 19, 2026

Modified: May 20, 2026

PUBLISHED

Description

Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system

VendorProductVersions

Jaspersoft

JasperReports Library Community Edition

affected
0 - <= 7.0.6

Jaspersoft

Jaspersoft Studio Community Edition

affected
0 - <= 7.0.6

Jaspersoft

JasperReports Server

affected
0 - <= 10.0.0

Jaspersoft

JasperReports Library Professional

affected
0 - <= 10.0.0

Jaspersoft

Jaspersoft Studio Professional

affected
0 - <= 10.0.0

Jaspersoft

JasperReports IO Professional

affected
0 - <= 10.0.0

Jaspersoft

JasperReports IO At-Scale

affected
0 - <= 10.0.0

Jaspersoft

JasperReports Web Studio

affected
0 - <= 10.0.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now