CVE-2026-21229Improper Input Validation in Microsoft Power BI Report Server

Severity
8.8HIGHNVD
CNA8.0
EPSS
0.1%
top 81.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 10

Description

Improper input validation in Power BI allows an authorized attacker to execute code over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5microsoft/power_bi_report_server1.6.015.0.1120.113

🔴Vulnerability Details

2
CVEList
Power BI Remote Code Execution Vulnerability2026-02-10
GHSA
GHSA-9h3x-5px3-gfh7: Improper input validation in Power BI allows an authorized attacker to execute code over a network2026-02-10

📋Vendor Advisories

1
Microsoft
Power BI Remote Code Execution Vulnerability2026-02-10
CVE-2026-21229 — Improper Input Validation in Microsoft | cvebase