CVE-2026-21229
Microsoft · Published February 10, 2026
8.0
CVSS v3.1
HIGHPatch availableGet patch
Description
Power BI Remote Code Execution Vulnerability. Improper input validation in Power BI allows an authorized attacker to execute code over a network.
Affected Products
- Power BI Report Server
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C