What is CVE-2026-65688?
CVE-2026-65688 is a missing filepath validation vulnerability in Bold Reports Standalone Report Designer before version 14.1.12. It allows unauthenticated attackers to read arbitrary files from the server filesystem via a crafted request exploiting path traversal. Upgrading to version 14.1.12 or later is required to mitigate this issue.
Azərbaycanca: CVE-2026-65688 Bold Reports Standalone Report Designer-in 14.1.12-dən əvvəlki versiyalarında mövcud olan "missing filepath validation" zəifliyidir. Bu boşluq autentifikasiya olunmamış hücumçulara xüsusi hazırlanmış sorğu vasitəsilə server fayl sistemindən ixtiyari faylları oxumağa imkan verir. Problemi aradan qaldırmaq üçün proqramı 14.1.12 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Bold Reports
FAQ2
Which versions of Bold Reports are affected by CVE-2026-65688 and how is it mitigated?
This vulnerability affects Bold Reports Standalone Report Designer versions prior to 14.1.12. Upgrading to version 14.1.12 or later is required to mitigate the issue.
What can an unauthenticated attacker achieve by exploiting CVE-2026-65688?
An unauthenticated attacker can read arbitrary files from the server filesystem by sending a crafted request that exploits path traversal.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.