PatchSiren

Bold Reports (By SyncFusion) CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Bold Reports (By SyncFusion) CVE published 2026-07-23

CVE-2026-65689

CVE-2026-65689 is a critical path traversal vulnerability in Bold Reports Standalone Report Designer before version 14.1.12. The vulnerability allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request to the database download feature in the DataHub module. This module was introduced in Bold Reports 6.3, so versions prior to 6.3 are not affected. The [truncated]