Executive brief
Bold Reports Standalone Report Designer, a tool used for creating and managing business reports, contains a security flaw in its database download feature. An unauthenticated attacker can exploit this to download sensitive files directly from the server's filesystem. This could lead to the theft of login credentials or other confidential data, potentially allowing an attacker to take full control of the application.
Technical details
A path traversal vulnerability (CWE-22) exists in Bold Reports Standalone Report Designer versions prior to 14.1.12. The flaw is located within the database download functionality, which fails to properly validate user-supplied file paths. An unauthenticated remote attacker can exploit this by sending a specially crafted request to access files outside of the intended directory. Successful exploitation allows for the retrieval of sensitive system files, including configuration data and authentication credentials, which can be leveraged for further compromise of the host or application. The issue is resolved in version 14.1.12.
Affected products
- Bold Reports (By Syncfusion) Standalone Report Designer before 14.1.12
Timeline
- 2026-07-20: patched: Vendor released version 14.1.12 to address the issue.
- 2026-07-23: disclosed: Vulnerability details and CVE-2026-65689 published.