Microsoft Power Bi Report Server vulnerabilities
7 known vulnerabilities affecting microsoft/power_bi_report_server.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2026-65811P2HIGHCVSS 8.8fixed in 15.0.1121.120≥ 1.6.0, < 1.26.9682.14422026-08-11
CVE-2026-65811 [HIGH] CWE-20 CVE-2026-65811: Improper input validation in Power BI allows an authorized attacker to execute code over a network.
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
nvd
CVE-2026-21229P2HIGHCVSS 8.8fixed in 15.0.1120.113≥ 1.6.0, < 1.25.9508.32372026-02-10
CVE-2026-21229 [HIGH] CWE-20 CVE-2026-21229: Improper input validation in Power BI allows an authorized attacker to execute code over a network.
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
nvd
CVE-2021-41372P3CRITICALCVSS 9.6v15.0.1107.1652021-11-10
CVE-2021-41372 [CRITICAL] CWE-79 CVE-2021-41372: A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power B
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim.
Combining these 2 vulnerabilities together, an attacker is able to upload malicious Power BI templates files to t
nvd
CVE-2019-1332P4MEDIUMCVSS 6.1vunspecified2019-12-10
CVE-2019-1332 [MEDIUM] CWE-79 CVE-2019-1332: A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'.
nvd
CVE-2020-1173P3MEDIUMCVSS 6.8≥ 1.6.0, < 1.6.7364.40752020-05-21
CVE-2020-1173 [MEDIUM] CWE-20 CVE-2020-1173: A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the cont
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An authenticated attacker could exploit the vulnerability by uploading a specially crafted payload and sending it to the user.
The attacker who successfully exploited this vulnerability could then perform actions and run
nvd
CVE-2021-26859P4MEDIUMCVSS 6.5v15.0.1103.234v15.0.1104.3002021-03-11
CVE-2021-26859 [MEDIUM] CVE-2021-26859: Microsoft Power BI Information Disclosure Vulnerability
Microsoft Power BI Information Disclosure Vulnerability
nvd
CVE-2026-58647P4MEDIUMCVSS 5.4fixed in 15.0.1121.120≥ 1.6.0, < 1.26.9682.14422026-07-14
CVE-2026-58647 [MEDIUM] CWE-79 CVE-2026-58647: Improper neutralization of input during web page generation ('cross-site scripting') in Power BI all
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
nvd