Description
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
Published: 2026-07-14
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The reported weakness is a cross‑site scripting flaw in Microsoft Power BI Report Server, arising from improper neutralization of user input during web page generation. An attacker with authorized access can inject malicious scripts that the server renders for clients, allowing the attacker to perform spoofing over a network by forging identities or data presented in reports. The vulnerability is categorized as CWE‑79.

Affected Systems

Microsoft Power BI Report Server is affected. Because no specific vulnerable versions were enumerated in the advisory, any instance that has not applied the security update for CVE‑2026‑58647 remains at risk.

Risk and Exploitability

The CVSS score of 8 indicates high severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector appears to be the web interface of the report server, requiring authorized access to inject and trigger malicious scripts, which could then be used to spoof user identities or data over the network.

Generated by OpenCVE AI on July 31, 2026 at 09:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for Power BI Report Server that addresses CVE‑2026‑58647.
  • Enforce least privilege by restricting report‑creation and administrative rights to trusted personnel.
  • Configure the web server to enforce strict input validation and XSS protection headers, and consider placing the Power BI Report Server behind a web application firewall that blocks suspicious script payloads.

Generated by OpenCVE AI on July 31, 2026 at 09:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
Title Microsoft PowerBI Report Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft power Bi Report Server
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:power_bi_report_server:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft power Bi Report Server
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Power Bi Report Server
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:53:55.550Z

Reserved: 2026-07-01T21:14:44.619Z

Link: CVE-2026-58647

cve-icon Vulnrichment

Updated: 2026-07-15T13:43:50.965Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:15:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')