Junglewise Threat Intelligence

CVE-2026-65811: Microsoft Power BI improper input validation RCE

CVE-2026-65811 · Severity: high · CVSS 8.8 · Published 2026-08-11

Technologies: Microsoft Power BI Report Server. Vendors: Microsoft.

Executive brief

Power BI is Microsoft's business intelligence platform used to analyze and visualize corporate data. An attacker with valid credentials can send specially crafted network requests to execute arbitrary code on affected systems, potentially compromising data integrity, availability, and confidentiality of sensitive business analytics.

Technical details

The vulnerability is an improper input validation flaw in Power BI that enables remote code execution. An authenticated attacker can craft malicious input that bypasses validation controls and execute arbitrary code on the affected system over the network. The vulnerability requires valid authentication credentials and network access to the Power BI service. Successful exploitation allows an attacker to execute code with the privileges of the Power BI service, potentially leading to complete system compromise. A patch is available from Microsoft.

Affected products

  • Microsoft Power BI <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats