CVE-2026-65687

Severity CVSS v4.0:
CRITICAL
Type:
CWE-22 Path Traversal
Publication date:
23/07/2026
Last modified:
23/07/2026

Description

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application.