CRITICAL
Bold Reports (By SyncFusion)
CVE published 2026-07-23
CVE-2026-65689
CVE-2026-65689 is a critical path traversal vulnerability in Bold Reports Standalone Report Designer before version 14.1.12. The vulnerability allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request to the database download feature in the DataHub module. This module was introduced in Bold Reports 6.3, so versions prior to 6.3 are not affected. The [truncated]