Description
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application. The vulnerability is specific to the DataHub module, which was introduced in Bold Reports 6.3. Therefore, versions prior to 6.3 are not affected.
Published: 2026-07-23
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Bold Reports Standalone Report Designer versions before 14.1.12 contain a missing file‑path validation in the font processing feature that allows unauthenticated attackers to read any file on the server by supplying a crafted request. This missing validation enables path‑traversal attacks that can disclose sensitive files such as authentication credentials and other confidential data, effectively giving attackers full uncontrolled access to the application and its underlying file system.

Affected Systems

The vulnerable component is the DataHub module of Bold Reports Standalone Report Designer, introduced in version 6.3. All releases of the product from 6.3 up to and including 14.1.11 are affected. Versions prior to 6.3 do not contain the DataHub module and are therefore not vulnerable.

Risk and Exploitability

With a CVSS score of 9.3 the vulnerability is considered critical. While the EPSS score is a very low probability of exploitation, the path‑traversal flaw can be triggered remotely through a network‑facing request without authentication, and the flaw is not listed in CISA’s KEV catalog. Attackers could hijack the application after reading confidential files.

Generated by OpenCVE AI on August 3, 2026 at 21:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade to Bold Reports Standalone Report Designer 14.1.12 or later
  • If immediate upgrade is not possible, disable or restrict access to the DataHub module's font processing endpoint to prevent unauthenticated requests
  • Implement network segmentation or firewall rules to isolate the server from external exposure, reducing the surface for remote exploitation

Generated by OpenCVE AI on August 3, 2026 at 21:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application. Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application. The vulnerability is specific to the DataHub module, which was introduced in Bold Reports 6.3. Therefore, versions prior to 6.3 are not affected.
Title Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via Font Processing Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Font Processing

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Bold Reports
Bold Reports standalone Report Designer
Vendors & Products Bold Reports
Bold Reports standalone Report Designer
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application.
Title Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via Font Processing
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Bold Reports Standalone Report Designer
Syncfusion Standalone Report Designer
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-24T14:32:24.855Z

Reserved: 2026-07-22T20:26:09.979Z

Link: CVE-2026-65688

cve-icon Vulnrichment

Updated: 2026-07-23T15:44:47.193Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-23T14:18:03.163

Modified: 2026-07-28T15:56:12.793

Link: CVE-2026-65688

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:30:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')