CVE-2026-65687
Bold Reports Standalone Report Designer versions before 14.1.12 contain a path‑traversal flaw in SVG processing that lets attackers read any file on the server. The flaw can expose sensitive data, including credentials, and give attackers full control of the application. It affects the DataHub module introduced in Bold Reports 6.3.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Bold Reports Standalone Report Designer versions prior to 14.1.12 that use the DataHub module (introduced in version 6.3).
Real-world impact
An attacker can read arbitrary files on the server, including authentication credentials, enabling full unauthorized access to the application.
Why this severity
The CVSS score of 9.3 reflects the high impact: the vulnerability allows attackers to read any file on the server without authentication or user interaction, leading to potential full compromise of the application.
What to do about it
- 01Upgrade Bold Reports Standalone Report Designer to version 14.1.12 or later.
- 02Restart the application to apply the update.
NVD description
Timeline
- Jul 23, 2026 · 9d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 8d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 28, 2026 · 4d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- boldreports.com/resources/release-history/s…release notes
- vulncheck.com/advisories/bold-reports-sta…third party advisory