CVE-2026-6009: CWE-502 Deserialization of untrusted data in Jaspersoft JasperReports Library Community Edition
CVE-2026-6009 is a high-severity vulnerability in the Jaspersoft JasperReports Library Community Edition caused by deserialization of untrusted data. This Java deserialization flaw can allow remote code execution without user interaction. The vulnerability has a CVSS 4.0 base score of 8.7, indicating a high impact with a network attack vector. No official patch or remediation guidance is currently available from the vendor. There are no known exploits in the wild at this time.
AI Analysis
Technical Summary
CVE-2026-6009 is a vulnerability in the Jaspersoft JasperReports Library Community Edition involving unsafe deserialization of untrusted data. This flaw can be exploited remotely without user interaction to execute arbitrary code on affected systems. The vulnerability has a CVSS 4.0 score of 8.7, reflecting high impact and exploitability. The vendor has not provided any official patch or remediation guidance as of the publication date. No known exploits have been reported in the wild.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code remotely on affected systems running the vulnerable JasperReports Library Community Edition. This could lead to full system compromise depending on the privileges of the affected application. The vulnerability requires no user interaction and can be triggered over the network.
Mitigation Recommendations
No official patch or remediation guidance is currently available from the vendor. Users should monitor the vendor's advisories for updates and consider applying defensive measures such as restricting network access to the affected service or using application-level controls to limit deserialization of untrusted data until a fix is released.
CVE-2026-6009: CWE-502 Deserialization of untrusted data in Jaspersoft JasperReports Library Community Edition
Description
CVE-2026-6009 is a high-severity vulnerability in the Jaspersoft JasperReports Library Community Edition caused by deserialization of untrusted data. This Java deserialization flaw can allow remote code execution without user interaction. The vulnerability has a CVSS 4.0 base score of 8.7, indicating a high impact with a network attack vector. No official patch or remediation guidance is currently available from the vendor. There are no known exploits in the wild at this time.
CVSS v4.0
Score 8.7high
Affected software
pkg:maven/com.jaspersoft/jasperreportsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-6009 is a vulnerability in the Jaspersoft JasperReports Library Community Edition involving unsafe deserialization of untrusted data. This flaw can be exploited remotely without user interaction to execute arbitrary code on affected systems. The vulnerability has a CVSS 4.0 score of 8.7, reflecting high impact and exploitability. The vendor has not provided any official patch or remediation guidance as of the publication date. No known exploits have been reported in the wild.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code remotely on affected systems running the vulnerable JasperReports Library Community Edition. This could lead to full system compromise depending on the privileges of the affected application. The vulnerability requires no user interaction and can be triggered over the network.
Mitigation Recommendations
No official patch or remediation guidance is currently available from the vendor. Users should monitor the vendor's advisories for updates and consider applying defensive measures such as restricting network access to the affected service or using application-level controls to limit deserialization of untrusted data until a fix is released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Jaspersoft
- Date Reserved
- 2026-04-09T14:16:26.621Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a0ca2183cb6383434df1625
Added to database: 05/19/2026, 17:47:04 UTC
Last enriched: 07/11/2026, 09:46:31 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 479
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.