CVE-2026-65690

Severity CVSS v4.0:
HIGH
Type:
CWE-22 Path Traversal
Publication date:
23/07/2026
Last modified:
23/07/2026

Description

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute arbitrary commands with high privileges on the server.