What is CVE-2026-65687?
CVE-2026-65687 is a missing filepath validation vulnerability in the SVG processing feature of Bold Reports Standalone Report Designer before version 14.1.12. It allows unauthenticated attackers to read arbitrary files from the server filesystem via crafted requests exploiting path traversal. Affected users should upgrade to version 14.1.12 or later immediately.
Azərbaycanca: CVE-2026-65687, Bold Reports Standalone Report Designer-in 14.1.12-dən əvvəlki versiyalarında SVG emalı funksiyasında "missing filepath validation" (çatışmayan fayl yolu yoxlaması) zəifliyidir. Bu, autentifikasiya olunmamış hücumçuya xüsusi hazırlanmış sorğu göndərərək server fayl sistemindən ixtiyari faylları oxumağa imkan verir. Təsirə məruz qalan sistemlər dərhal 14.1.12 və ya daha yeni versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Bold Reports
FAQ2
Does exploiting CVE-2026-65687 require authentication?
No, the vulnerability allows an unauthenticated attacker to exploit it by sending a crafted request.
To which version should users upgrade to protect against CVE-2026-65687?
Affected systems should be upgraded to Bold Reports Standalone Report Designer version 14.1.12 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.