Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bold Reports
Bold Reports standalone Report Designer |
|
| Vendors & Products |
Bold Reports
Bold Reports standalone Report Designer |
|
| Metrics |
ssvc
|
Thu, 23 Jul 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute arbitrary commands with high privileges on the server. | |
| Title | Bold Reports Standalone Report Designer 14.1.12 Path Traversal RCE via File Upload | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-23T15:53:40.478Z
Reserved: 2026-07-22T20:26:09.979Z
Link: CVE-2026-65690
Updated: 2026-07-23T15:53:36.477Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-23T20:09:42Z