Executive brief
Power BI is Microsoft's business analytics and data visualization platform used by enterprises to analyze and share insights. An improper input validation flaw allows authorized users to execute arbitrary code over the network, which could lead to unauthorized system compromise, data theft, or lateral movement within an organization.
Technical details
The vulnerability stems from improper input validation in Power BI that fails to sanitize user-supplied data before processing. An authenticated attacker can craft malicious input to trigger code execution through a network-accessible interface. The attack requires valid credentials (authorized attacker), but once exploited allows remote code execution with the privileges of the Power BI service. Patches should be available from Microsoft through their standard update mechanisms.
Affected products
- Microsoft Power BI
Timeline
- 2026-02-10: disclosed