Cross-Site Scripting Vulnerability in Microsoft Power BI
CVE-2026-58647

8HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
14 July 2026

What is CVE-2026-58647?

An issue has been identified in Microsoft Power BI that involves improper handling of user input during the web page generation process, leading to potential cross-site scripting vulnerabilities. This flaw allows an authorized attacker to exploit the system and perform spoofing attacks over a network, posing a risk to data integrity and user trust. It is essential for users and administrators to apply recommended patches and updates to mitigate this risk effectively.

Affected Version(s)

Power BI Report Server 1.6.0 < 15.0.1121.120

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.