CVE-2026-65811ImportantRevised 19 Aug
Power BI Remote Code Execution Vulnerability
Assessment
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
- Severity
- Important
- CVSS base score
- 8.8CVSS:3.1/
AV:N/ AC:L/ PR:L/ UI:N/ S:U/ C:H/ I:H/ A:H/ E:U/ RL:O/ RC:C - Impact
- Remote Code Execution
- EPSS, next 30 days
- 1.0%Higher than 59.9% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation Less Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Power BI
- Weakness
- CWE-20: Improper Input Validation
- Issued by
- Microsoft
- Published
- 11 Aug 2026 · August 2026
- Last revised
- 19 Aug 2026Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.
Affected products
SQL Server1 affected product
- Power BI Report Server