CVE-2026-65689
Bold Reports Standalone Report Designer versions before 14.1.12 contain a path‑traversal flaw that lets attackers read any file on the server. The weakness is in the DataHub module and can expose credentials, giving attackers full control of the application. It is critical because it requires no authentication and can be exploited remotely.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Bold Reports Standalone Report Designer 6.3 through 14.1.11 (any version with the DataHub module).
Real-world impact
An attacker can read arbitrary files, including authentication credentials, and gain full unauthorized access to the application.
Why this severity
The CVSS score of 9.3 reflects the lack of authentication, the ability to read any file, and the high impact on confidentiality, integrity, and availability. The vulnerability is remote, low effort, and has a high potential for damage.
What to do about it
- 01Verify the current Bold Reports Standalone Report Designer version.
- 02If the version is older than 14.1.12, download and install the latest release (14.1.12 or newer) from the vendor.
- 03Restart the application to apply the update.
NVD description
Timeline
- Jul 23, 2026 · 9d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 8d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 28, 2026 · 4d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- boldreports.com/resources/release-history/s…release notes
- vulncheck.com/advisories/bold-reports-sta…third party advisory