Description
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application. The vulnerability is specific to the DataHub module, which was introduced in Bold Reports 6.3. Therefore, versions prior to 6.3 are not affected.
Published: 2026-07-23
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Bold Reports Standalone Report Designer before version 14.1.12 contains a missing filepath validation flaw in its SVG processing feature that allows an attacker to supply a specially crafted request a classic path traversal weakness that can expose sensitive configuration files or authentication data, effectively granting the attacker full unauthorized access to the application’s backend. The impact is a breach of confidentiality and could serve as a stepping stone to further compromise of the system.

Affected Systems

The affected vendor and product are Bold Reports (By SyncFusion) Standalone Report Designer. Versions prior to 14.1.12 are vulnerable, and the flaw exists only in releases that include the DataHub module introduced from Bold Reports 6.3 onward. Earlier releases before 6.3 are not affected.

Risk and Exploitability

The EPSS score of less than 1% indicates a low probability of active exploitation at present, yet the CVSS score of 9.3 still reflects a severe risk should exploitation occur. The flaw is unauthenticated and is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability by sending a crafted request to the SVG processing endpoint, allowing them to read arbitrary files from the server filesystem without authentication.

Generated by OpenCVE AI on August 4, 2026 at 15:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Bold Reports Standalone Report Designer version 14.1.12 or newer, which removes the unchecked path traversal flaw (CWE‑22).
  • If an upgrade cannot be performed immediately, enforce rigorous input validation on the SVG processing endpoint and limit its exposure so that only authorized internal users can trigger it, thereby mitigating the CWE‑22 path traversal risk.
  • Regularly review web‑server logs for anomalous file requests that may indicate exploitation attempts, and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 4, 2026 at 15:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application. Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application. The vulnerability is specific to the DataHub module, which was introduced in Bold Reports 6.3. Therefore, versions prior to 6.3 are not affected.
Title Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via SVG Processing Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via SVG Processing

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Bold Reports
Bold Reports standalone Report Designer
Vendors & Products Bold Reports
Bold Reports standalone Report Designer
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application.
Title Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via SVG Processing
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Bold Reports Standalone Report Designer
Syncfusion Standalone Report Designer
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-24T14:32:12.957Z

Reserved: 2026-07-22T20:26:09.979Z

Link: CVE-2026-65687

cve-icon Vulnrichment

Updated: 2026-07-23T15:36:58.753Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-23T14:18:02.993

Modified: 2026-07-28T15:57:12.643

Link: CVE-2026-65687

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:30:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')