Bold Reports vulnerabilities
4 CVEs tracked
Bold Reports appears in recent reporting as a vendor with a product, Standalone Report Designer, containing multiple missing filepath validation vulnerabilities. These flaws enable attackers to read arbitrary files from the server filesystem, with three CVEs covering unauthenticated attacks via the database download, font, and SVG processing features (CVE-2026-65689, CVE-2026-65688, CVE-2026-65687) and one CVE covering an authenticated directory traversal via file upload (CVE-2026-65690). Defenders should prioritize patching to version 14.1.12 and monitor access to the mentioned product functionalities.
Azərbaycanca: Bold Reports, hesabat mühitində istifadə olunan bir vendor kimi qeyd edilir. Son hesabatlara əsasən, onun Standalone Report Designer məhsulunda autentifikasiya olmamış və autentifikasiya olunmuş hücumçuların server fayl sistemindən ixtiyari faylları oxumasına imkan verən bir neçə 'missing filepath validation' (çatışmayan fayl yolunun yoxlanması) zəifliyi aşkar edilib. Əsas diqqət CVE-2026-65689, CVE-2026-65688, CVE-2026-65687 (verilənlər bazası yükləmə, font və SVG emalı xüsusiyyətlərini təsirləyən autentifikasiyasız hücumlar) və autentifikasiyalı kataloqdan kənara çıxma (directory traversal) hücumuna şərait yaradan CVE-2026-65690 üzərində cəmlənməlidir. Müdafiəçilər dərhal 14.1.12 versiyasına yeniləmə aparmalı və bu spesifik funksional komponentlərə girişi monitorinq etməlidir.
This vendor's CVEs4
This hub is built from skopnix's own reporting on Bold Reports: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.