Executive brief
Bold Reports Standalone Report Designer, a tool used for creating and managing business reports, contains a security flaw in how it handles font files. An unauthenticated attacker can exploit this to read sensitive files directly from the server's filesystem, such as configuration files or login credentials. This could lead to a total compromise of the reporting server and unauthorized access to corporate data.
Technical details
A path traversal vulnerability (CWE-22) exists in the font processing feature of Bold Reports Standalone Report Designer due to insufficient validation of user-supplied file paths. An unauthenticated remote attacker can exploit this by sending a specially crafted network request to the server. Successful exploitation allows the attacker to read arbitrary files from the underlying host filesystem. This can result in the disclosure of sensitive information, including application credentials, which may facilitate further unauthorized access or full system compromise. The issue is resolved in version 14.1.12.
Affected products
- Bold Reports (By Syncfusion) Standalone Report Designer < 14.1.12
Timeline
- 2026-07-20: patched: Vendor released version 14.1.12
- 2026-07-23: disclosed: CVE-2026-65688 published