Description
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute arbitrary commands with high privileges on the server. The vulnerability is specific to the DataHub module, which was introduced in Bold Reports 6.3. Therefore, versions prior to 6.3 are not affected.
Published: 2026-07-23
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing filepath validation vulnerability in the file upload feature of Bold Reports Standalone Report Designer allows attackers to supply a crafted filename that traverses outside the intended directory and cause the server to execute arbitrary commands with the privileges of the underlying process. The flaw is confined to the DataHub module introduced in Bold Reports 6.3, so installations prior to 6.3 are unaffected.

Affected Systems

Bold Reports Standalone Report Designer (By SyncFusion) versions prior to 14.1.12 that include the DataHub module (introduced in Bold Reports 6.3) are vulnerable. Versions released before 6.3 do not contain the DataHub module and are not impacted.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score of <1% indicates a low statistical probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access to the file upload function. An attacker with legitimate but potentially untrusted credentials can upload a crafted file name, causing the server to execute arbitrary commands with high privileges. The risk is confined to systems running the vulnerable module and having valid usernames and passwords, implying that strong authentication controls are a primary mitigator.

Generated by OpenCVE AI on August 3, 2026 at 21:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Bold Reports Standalone Report Designer to version 14.1.12 or newer, which removes the missing filepath validation bug in the DataHub module.
  • If an upgrade is not immediately feasible, restrict the file upload feature to the least privileged users and enforce strict authentication control so that only trusted accounts can upload files.
  • Implement filename validation or path sanitization in the upload workflow to ensure that any supplied filename cannot escape the intended directory before the file is stored.

Generated by OpenCVE AI on August 3, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute arbitrary commands with high privileges on the server. Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute arbitrary commands with high privileges on the server. The vulnerability is specific to the DataHub module, which was introduced in Bold Reports 6.3. Therefore, versions prior to 6.3 are not affected.
Title Bold Reports Standalone Report Designer 14.1.12 Path Traversal RCE via File Upload Bold Reports Standalone Report Designer < 14.1.12 Path Traversal RCE via File Upload

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Bold Reports
Bold Reports standalone Report Designer
Vendors & Products Bold Reports
Bold Reports standalone Report Designer
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute arbitrary commands with high privileges on the server.
Title Bold Reports Standalone Report Designer 14.1.12 Path Traversal RCE via File Upload
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Bold Reports Standalone Report Designer
Syncfusion Standalone Report Designer
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-24T14:34:37.299Z

Reserved: 2026-07-22T20:26:09.979Z

Link: CVE-2026-65690

cve-icon Vulnrichment

Updated: 2026-07-23T15:53:36.477Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-23T14:18:03.503

Modified: 2026-07-28T15:55:00.480

Link: CVE-2026-65690

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:30:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')