CVE-2026-65689

Bold Reports (By SyncFusion) · Standalone Report Designer

Bold Reports Standalone Report Designer contains a path traversal vulnerability in its database download feature, allowing unauthenticated attackers to read arbitrary files from the server.

Executive summary

A critical path traversal vulnerability in the Bold Reports Standalone Report Designer allows unauthenticated attackers to read sensitive files from the server filesystem.

Vulnerability

The application fails to validate filepaths within its database download feature, which constitutes a path traversal vulnerability (CWE-22). An unauthenticated attacker can supply crafted requests to read sensitive configuration files or authentication credentials, leading to full unauthorized access to the application.

Business impact

The exposure of sensitive server files, including credentials, provides an attacker with the necessary information to achieve full system compromise. This vulnerability allows for unauthorized access to internal application data and potentially the underlying server infrastructure. The CVSS score of 9.8 highlights the critical nature of this disclosure vulnerability.

Remediation

Immediate Action: Upgrade to Bold Reports Standalone Report Designer version 14.1.12 or higher.

Proactive Monitoring: Review system logs for unusual file access requests, particularly those involving directory traversal characters or attempts to access configuration files.

Compensating Controls: Ensure the application is isolated from public networks where possible, and use a WAF to restrict incoming requests to expected patterns.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability requires immediate action to update the software to version 14.1.12. Administrators should prioritize this patch to prevent potential credential theft and full application compromise resulting from the path traversal flaw.