CVE-2026-58647ImportantRevised 19 Aug
Microsoft PowerBI Report Server Spoofing Vulnerability
Assessment
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
- Severity
- Important
- CVSS base score
- 8.0CVSS:3.1/
AV:N/ AC:L/ PR:L/ UI:R/ S:U/ C:H/ I:H/ A:H/ E:U/ RL:O/ RC:C - Impact
- Spoofing
- EPSS, next 30 days
- 0.5%Higher than 42.1% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation Unlikely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Power BI
- Weakness
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Issued by
- Microsoft
- Published
- 14 Jul 2026 · July 2026
- Last revised
- 19 Aug 2026Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.
Affected products
SQL Server1 affected product
- Power BI Report Server