PatchSiren

Bold Reports (By SyncFusion) CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Bold Reports (By SyncFusion) CVE published 2026-07-23

CVE-2026-65690

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute arbitrary commands with high privileges on the server. The vulnerability is specific to the D [truncated]

CRITICAL Bold Reports (By SyncFusion) CVE published 2026-07-23

CVE-2026-65689

CVE-2026-65689 is a critical path traversal vulnerability in Bold Reports Standalone Report Designer before version 14.1.12. The vulnerability allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request to the database download feature in the DataHub module. This module was introduced in Bold Reports 6.3, so versions prior to 6.3 are not affected. The [truncated]

CRITICAL Bold Reports (By SyncFusion) CVE published 2026-07-23

CVE-2026-65688

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T14:18:03.163Z and has not been modified since then. The Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature. This allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying [truncated]

CRITICAL Bold Reports (By SyncFusion) CVE published 2026-07-23

CVE-2026-65687

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T14:18:02.993Z and has not been modified since then. CVE-2026-65687 is a critical vulnerability in Bold Reports Standalone Report Designer before version 14.1.12, specifically in the DataHub module introduced in version 6.3. This module's SVG processing feature lacks filepath validation, allowing [truncated]