CVE-2026-65690
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
23/07/2026
Last modified:
23/07/2026
Description
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute arbitrary commands with high privileges on the server.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH



