CVE-2026-65690 PUBLISHED

Bold Reports Standalone Report Designer 14.1.12 Path Traversal RCE via File Upload

Assigner: VulnCheck
Reserved: 22.07.2026 Published: 23.07.2026 Updated: 23.07.2026

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute arbitrary commands with high privileges on the server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Bold Reports (By SyncFusion)
Product Standalone Report Designer
Versions Default: affected
  • affected from 0 to 14.1.12 (excl.)

Credits

  • Sina Kheirkhah (SinSinology) of watchTowr (watchTowrCyber) finder

References

Problem Types

  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE