PT-2026-63998 · Bold Reports+1 · Standalone Report Designer

·

CVE-2026-65688

·

Published

2026-07-23

·

Updated

2026-07-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bold Reports Standalone Report Designer versions 6.3 through 14.1.11
Description A missing filepath validation in the font processing feature of the DataHub module allows unauthenticated attackers to read arbitrary files from the server filesystem via a crafted request. This path traversal weakness can be used to disclose sensitive server files, such as authentication credentials, potentially leading to full unauthorized access to the application.
Recommendations Update Bold Reports Standalone Report Designer to version 14.1.12.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65688

Affected Products

Standalone Report Designer