What is CVE-2026-65689?
Bold Reports Standalone Report Designer versions prior to 14.1.12 contain a missing filepath validation vulnerability in the database download feature. This allows unauthenticated attackers to read arbitrary files from the server filesystem via a crafted request. Affected systems should be immediately updated to version 14.1.12 or later.
Azərbaycanca: Bold Reports Standalone Report Designer-in 14.1.12 versiyasından əvvəlki versiyalarında, verilənlər bazası yükləmə funksionallığında fayl yolu doğrulamasının (filepath validation) olmaması zəifliyi aşkarlanıb. Bu boşluq autentifikasiya olunmamış hücumçulara xüsusi hazırlanmış sorğu vasitəsilə server fayl sistemindən ixtiyari faylları oxumağa imkan verir. Təsirlənən sistemlərdə dərhal 14.1.12 və ya daha yuxarı versiyaya yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Bold Reports
FAQ2
Which versions of Bold Reports are affected by CVE-2026-65689?
Versions of the Standalone Report Designer prior to 14.1.12 are affected.
What does this vulnerability allow an unauthenticated attacker to do?
It allows reading arbitrary files from the server filesystem via a crafted request.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.