Executive brief
Bold Reports Standalone Report Designer, a tool used for creating and managing business reports, contains a security flaw in its file upload feature. An authorized user can bypass security restrictions to upload files to unauthorized locations on the server. This could allow an attacker to take full control of the system, potentially leading to data theft or service disruption.
Technical details
A path traversal vulnerability (CWE-22) exists in the file upload functionality of Bold Reports Standalone Report Designer prior to version 14.1.12. The application fails to properly validate user-supplied filenames, allowing an authenticated attacker to use traversal sequences (e.g., ../) to write files outside of the designated upload directory. By uploading malicious files to sensitive locations, an attacker can achieve remote code execution (RCE) with high privileges. This vulnerability is reachable over the network but requires at least low-level authenticated access. Users should update to version 14.1.12 or later to remediate the issue.
Affected products
- Bold Reports (By Syncfusion) Standalone Report Designer < 14.1.12
Timeline
- 2026-07-20: patched: Vendor released version 14.1.12 fixing the issue.
- 2026-07-23: advisory: CVE-2026-65690 published.