NPM · JULY 2026 · CONFIRMED

Bold Reports Standalone Report Designer <= 14.1.11 Vulnerability Threat

CVE-2026-65688Severity: CRITICAL

A critical vulnerability has been confirmed in Bold Reports Standalone Report Designer versions before 14.1.12, enabling unauthenticated attackers to read arbitrary files from the server filesystem.

What happened

Bold Reports Standalone Report Designer versions before 14.1.12 contain a missing filepath validation vulnerability in its font processing feature (CVE-2026-65688), SVG processing feature (CVE-2026-65687), and database download feature (CVE-2026-65689). This allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application.

To assess your exposure, check if you are using Bold Reports Standalone Report Designer version 14.1.12 or later. If not, it is recommended to upgrade to version 14.1.12 or later to mitigate the risk. For more detailed information, consult the primary sources: [CVE-2026-65687](https://nvd.nist.gov/vuln/detail/CVE-2026-65687), [CVE-2026-65688](https://nvd.nist.gov/vuln/detail/CVE-2026-65688), and [CVE-2026-65689](https://nvd.nist.gov/vuln/detail/CVE-2026-65689).

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If bold reports is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats