What is CVE-2026-65690?
This vulnerability exists in the file upload functionality of Bold Reports Standalone Report Designer before version 14.1.12. An authenticated attacker can exploit a missing filepath validation to perform a path traversal attack by supplying a crafted filename, potentially writing files outside the intended directory. Users should immediately update to version 14.1.12 or later.
Azərbaycanca: Bu zəiflik Bold Reports Standalone Report Designer-in 14.1.12-dən əvvəlki versiyalarında fayl yükləmə funksiyasında mövcuddur. Autentifikasiya olunmuş hücumçu xüsusi hazırlanmış fayl adı vasitəsilə path traversal həyata keçirərək nəzərdə tutulan kataloqdan kənara çıxa bilər. İstifadəçilər dərhal 14.1.12 və ya daha yeni versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Bold Reports
FAQ2
Which versions of Bold Reports are affected by CVE-2026-65690?
This vulnerability exists in Bold Reports Standalone Report Designer before version 14.1.12.
Is authentication required to exploit the path traversal vulnerability in CVE-2026-65690?
Yes, an attacker must be authenticated to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.