Junglewise Threat Intelligence

CVE-2026-65687: Bold Reports Standalone Report Designer path traversal in SVG processing

CVE-2026-65687 · Severity: critical · CVSS 9.8 · Published 2026-07-23

Technologies: Bold Reports (By SyncFusion) Standalone Report Designer. Vendors: Syncfusion.

Executive brief

Bold Reports Standalone Report Designer, a tool used for creating and managing business reports, contains a security flaw in how it handles image files. An unauthenticated attacker can exploit this to read sensitive files directly from the server's storage, such as system configuration files or login credentials. This could lead to a complete takeover of the application and unauthorized access to corporate data.

Technical details

A path traversal vulnerability (CWE-22) exists in Bold Reports Standalone Report Designer versions prior to 14.1.12. The flaw is located within the SVG processing component, which fails to properly validate file paths provided in crafted requests. A remote, unauthenticated attacker can exploit this weakness to access sensitive files on the host operating system, including application credentials and configuration data. This vulnerability can be leveraged to achieve full unauthorized access to the application environment. The issue is addressed in version 14.1.12.

Affected products

  • Bold Reports (By SyncFusion) Standalone Report Designer before 14.1.12

Timeline

  • 2026-07-20: patched: Vendor released version 14.1.12 to address the issue.
  • 2026-07-23: advisory: NVD and VulnCheck published advisory details.

References

Related threats