PT-2026-63999 · Bold Reports+1 · Standalone Report Designer

·

CVE-2026-65689

·

Published

2026-07-23

·

Updated

2026-07-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bold Reports Standalone Report Designer versions 6.3 through 14.1.11
Description A missing filepath validation issue exists in the database download feature within the DataHub module. This path traversal weakness allows unauthenticated attackers to read arbitrary files from the server filesystem by sending a crafted request, potentially disclosing sensitive information such as authentication credentials and enabling unauthorized application access.
Recommendations Update Bold Reports Standalone Report Designer to version 14.1.12. Restrict access to the DataHub module to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65689

Affected Products

Standalone Report Designer