Junglewise Threat Intelligence

CVE-2026-21229: Microsoft Power BI improper input validation allows code execution

CVE-2026-21229 · Severity: high · CVSS 8 · Published 2026-02-10

Technologies: Microsoft Power BI Report Server. Vendors: Microsoft.

Executive brief

Power BI is Microsoft's business analytics and data visualization platform used by enterprises to analyze and share insights. An improper input validation flaw allows authorized users to execute arbitrary code over the network, which could lead to unauthorized system compromise, data theft, or lateral movement within an organization.

Technical details

The vulnerability stems from improper input validation in Power BI that fails to sanitize user-supplied data before processing. An authenticated attacker can craft malicious input to trigger code execution through a network-accessible interface. The attack requires valid credentials (authorized attacker), but once exploited allows remote code execution with the privileges of the Power BI service. Patches should be available from Microsoft through their standard update mechanisms.

Affected products

  • Microsoft Power BI

Timeline

  • 2026-02-10: disclosed

References

Related threats