CVE-2026-65811
8.8Microsoft · Power BI Report Server
Improper input validation in Microsoft Power BI Report Server allows an authenticated attacker to execute arbitrary code over a network.
Executive summary
A critical input validation vulnerability in Microsoft Power BI Report Server allows an authenticated attacker to achieve remote code execution.
Vulnerability
This vulnerability is classified as improper input validation (CWE-20). It requires the attacker to hold authenticated access, allowing them to leverage the flaw to execute arbitrary code within the context of the application.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute code with the privileges of the application, potentially leading to full system compromise. With a CVSS score of 8.8, this flaw represents a significant risk to data confidentiality, integrity, and availability, which could result in unauthorized access to sensitive business intelligence data and server infrastructure.
Remediation
Immediate Action: Update Microsoft Power BI Report Server to version 15.0.1121.120 or later as provided by the official Microsoft Security Update Guide.
Proactive Monitoring: Review server access logs for unusual requests or patterns originating from authenticated accounts that deviate from standard operational behavior.
Compensating Controls: Ensure the server is isolated within a secure network segment, and utilize a Web Application Firewall (WAF) to inspect incoming traffic for malformed input payloads.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the severity of this remote code execution flaw, organizations should prioritize testing and deploying the vendor-supplied update immediately. Administrators must verify that all instances of Power BI Report Server are patched to the specified version to mitigate the risk of unauthorized system access.