Vendor
high
advisory
Bold Reports Standalone Report Designer Path Traversal to RCE Vulnerability
1 rule 1 TTP 1 CVE 2 IOCsA missing filepath validation vulnerability (CVE-2026-65690) in Bold Reports Standalone Report Designer before version 14.1.12 allows authenticated attackers to perform path traversal via crafted filenames during file upload, leading to arbitrary command execution with high privileges.
Standalone Report Designer
vulnerability
path-traversal
rce
web-application
1r
1t
1c
2i
critical
advisory
CVE-2026-65689: Bold Reports Standalone Report Designer Path Traversal Vulnerability
1 rule 1 TTP 1 CVEA missing filepath validation vulnerability (CVE-2026-65689) in Bold Reports Standalone Report Designer before version 14.1.12 allows unauthenticated attackers to perform path traversal by sending a crafted request to the database download feature, enabling them to read arbitrary sensitive server files, including authentication credentials, and potentially gain full unauthorized access to the application.
Standalone Report Designer
path-traversal
vulnerability
web-application
arbitrary-file-read
cve
1r
1t
1c