Junglewise Threat Intelligence

CVE-2026-58647: Microsoft Power BI Report Server cross-site scripting

CVE-2026-58647 · Severity: high · CVSS 8 · Published 2026-07-14

Technologies: Microsoft Power BI Report Server. Vendors: Microsoft.

Executive brief

Microsoft Power BI Report Server, a platform for hosting and managing reports, is affected by a security vulnerability that could allow an attacker to perform spoofing attacks. An authorized user could exploit this flaw to execute malicious scripts in another user's browser session. This could lead to unauthorized access to sensitive data, session hijacking, or the manipulation of report content.

Technical details

A cross-site scripting (XSS) vulnerability exists in Microsoft Power BI Report Server due to improper neutralization of input during web page generation (CWE-79). An authenticated attacker with network access can exploit this by sending a specially crafted request to the server. Successful exploitation requires a victim to interact with a malicious link or page, allowing the attacker to execute arbitrary script in the context of the victim's browser. This can result in a full compromise of confidentiality, integrity, and availability for the affected user session. The vulnerability affects versions starting from 1.6.0 up to 15.0.1121.120.

Affected products

  • Microsoft Power BI Report Server 1.6.0 to 15.0.1121.120

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD.
  • 2026-07-14: disclosed

References

Related threats