CVE-2026-21229

8.0

Microsoft · Power BI Report Server

Improper input validation in Microsoft Power BI Report Server allows an authorized attacker to execute arbitrary code over a network.

Executive summary

A critical input validation vulnerability in Microsoft Power BI Report Server could allow an authenticated attacker to achieve remote code execution.

Vulnerability

This vulnerability is caused by improper input validation, classified as CWE-20, which enables an attacker with authorized access to trigger remote code execution over a network. The attack requires low privileges (authenticated) and user interaction, according to the CVSS vector.

Business impact

The potential for remote code execution poses a severe threat to the confidentiality, integrity, and availability of the affected system. Successful exploitation could lead to total system compromise, unauthorized data access, and potential lateral movement within the network. With a CVSS score of 8.0, this vulnerability represents a high-risk scenario that necessitates immediate prioritization by security teams.

Remediation

Immediate Action: Update Microsoft Power BI Report Server to version 1.25.9508.3237 or later as specified by the Microsoft security update guide.

Proactive Monitoring: Monitor system logs for unusual process execution or network traffic patterns originating from authorized user accounts.

Compensating Controls: Ensure that access to the Power BI Report Server is restricted to trusted internal networks and utilize WAF rules to inspect input traffic for anomalous payloads.

Exploitation status

Public Exploit Available: exploit_available (false)

Analyst recommendation

Given the high CVSS score and the potential for remote code execution, this vulnerability should be treated as a high-priority item for remediation. Organizations should verify their current version of Power BI Report Server and apply the provided security updates immediately to mitigate the risk of unauthorized command execution.

More Microsoft CVEs

Sources