CVE-2026-65688
Bold Reports Standalone Report Designer versions before 14.1.12 have a path‑traversal flaw in their font processing that lets attackers read any file on the server. The bug is limited to the DataHub module added in Bold Reports 6.3, so earlier releases are safe.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Bold Reports Standalone Report Designer, versions prior to 14.1.12, specifically those using the DataHub module introduced in Bold Reports 6.3. Versions before 6.3 are not affected.
Real-world impact
An attacker can supply a crafted request to read arbitrary files on the server, including authentication credentials, giving them full unauthorized access to the application.
Why this severity
The CVSS score of 9.3 reflects the vulnerability’s high confidentiality, integrity, and availability impact, combined with low attack complexity and no authentication or user interaction required.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 23, 2026 · 9d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 28, 2026 · 4d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- boldreports.com/resources/release-history/s…release notes
- vulncheck.com/advisories/bold-reports-sta…third party advisory