Jaspersoft Reports Library Java Deserialization Vulnerability Leading to Remote Code Execution

Vulnerability

A Java deserialization vulnerability has been identified in the Jaspersoft Reports Library. This vulnerability allows for remote code execution (RCE), potentially enabling an attacker to execute arbitrary code on the affected system.

Impact

Exploitation of this vulnerability could lead to remote code execution on the server where Jaspersoft Reports Library is used.

Added: May 19, 2026, 6:37 PM
Updated: May 19, 2026, 6:37 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
7.5
exploitability
6.8
remediation
0.0
relevance
8.8
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.