PT-2026-64000 · Bold Reports+1 · Standalone Report Designer

·

CVE-2026-65690

·

Published

2026-07-23

·

Updated

2026-07-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bold Reports Standalone Report Designer versions 6.3 through 14.1.11
Description A missing filepath validation issue exists in the file upload functionality within the DataHub module. Authenticated attackers can use a crafted filename to perform path traversal, allowing them to access directories outside the intended scope and execute arbitrary commands with high privileges on the server.
Recommendations Update Bold Reports Standalone Report Designer to version 14.1.12. Restrict access to the DataHub module to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65690

Affected Products

Standalone Report Designer