Java Deserialization RCE in Hitachi Energy Ellipse Reporting Component

Hitachi Energy Ellipse versions 9.0.50 and earlier include a vulnerable JasperReports library with a Java deserialization flaw (CVE-2025-10492). This flaw allows remote attackers to execute arbitrary code by exploiting the report generation feature. The vulnerability lies in a third-party component used to create custom reports, not in the core Ellipse application itself. Because the exploit targets the reporting functionality, network controls alone may not prevent attacks. Operators must update Ellipse to a fixed version or apply Hitachi Energy's mitigations, such as restricting report loading to trusted sources or disabling external report features. This is critical for organizations in manufacturing and critical infrastructure sectors using Ellipse worldwide.

Part of the PlainSec briefing for 2026-04-03

Sources