CVE-2026-65689 PUBLISHED

Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via Database Download

Assigner: VulnCheck
Reserved: 22.07.2026 Published: 23.07.2026 Updated: 23.07.2026

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Bold Reports (By SyncFusion)
Product Standalone Report Designer
Versions Default: affected
  • affected from 0 to 14.1.12 (excl.)

Credits

  • Sina Kheirkhah (SinSinology) of watchTowr (watchTowrCyber) finder

References

Problem Types

  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE