CVE-2026-65687

Bold Reports (By SyncFusion) · Standalone Report Designer

Bold Reports Standalone Report Designer is susceptible to an unauthenticated path traversal vulnerability, allowing remote attackers to read arbitrary files from the server filesystem.

Executive summary

An unauthenticated path traversal vulnerability in Bold Reports Standalone Report Designer allows attackers to read sensitive server files, posing a critical risk of full application compromise.

Vulnerability

This is a path traversal vulnerability caused by missing file path validation within the SVG processing feature. It allows an unauthenticated attacker to supply crafted requests to access files outside of the intended directory, including sensitive configuration and credential files.

Business impact

The ability to read arbitrary files from the server represents a critical security failure. An attacker could extract authentication tokens, database connection strings, or system configuration files, leading to complete unauthorized access to the application and the underlying server environment.

Remediation

Immediate Action: Update the Bold Reports Standalone Report Designer to version 14.1.12 or later to resolve the path validation flaw.

Proactive Monitoring: Monitor server access logs for requests containing directory traversal sequences, such as dot-dot-slash patterns, directed at the application.

Compensating Controls: Deploy a Web Application Firewall (WAF) to filter and block requests containing directory traversal attempts before they reach the application backend.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity and the potential for total system compromise, immediate remediation is required. Organizations must update the Standalone Report Designer to version 14.1.12 or newer to eliminate the path traversal vulnerability and protect sensitive server assets.