High severityNVD Advisory· Published May 19, 2026· Updated Jul 24, 2026
CVE-2026-6009
CVE-2026-6009
Description
Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
net.sf.jasperreports:jasperreportsMaven | < 7.0.7 | 7.0.7 |
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-9wxq-mwqw-8hhgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-6009ghsaADVISORY
- community.jaspersoft.com/advisories/jaspersoft-security-advisory-may-19-2026-jaspersoft-library-cve-2026-6009-r11ghsaWEB
- community.jaspersoft.com/advisories/jaspersoft-security-advisory-may-19-2026-jaspersoft-library-cve-2026-6009-r11/nvd
News mentions
0No linked articles in our index yet.