Executive brief
Power BI is Microsoft's business intelligence platform used to analyze and visualize corporate data. An attacker with valid credentials can send specially crafted network requests to execute arbitrary code on affected systems, potentially compromising data integrity, availability, and confidentiality of sensitive business analytics.
Technical details
The vulnerability is an improper input validation flaw in Power BI that enables remote code execution. An authenticated attacker can craft malicious input that bypasses validation controls and execute arbitrary code on the affected system over the network. The vulnerability requires valid authentication credentials and network access to the Power BI service. Successful exploitation allows an attacker to execute code with the privileges of the Power BI service, potentially leading to complete system compromise. A patch is available from Microsoft.
Affected products
- Microsoft Power BI <UNKNOWN>
Timeline
- 2026-08-11: disclosed