CyberICT

CVE-2026-21229

Microsoft · Published February 10, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Power BI Remote Code Execution Vulnerability. Improper input validation in Power BI allows an authorized attacker to execute code over a network.

Affected Products

  • Power BI Report Server

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C