Impact
The reported weakness is a cross‑site scripting flaw in Microsoft Power BI Report Server, arising from improper neutralization of user input during web page generation. An attacker with authorized access can inject malicious scripts that the server renders for clients, allowing the attacker to perform spoofing over a network by forging identities or data presented in reports. The vulnerability is categorized as CWE‑79.
Affected Systems
Microsoft Power BI Report Server is affected. Because no specific vulnerable versions were enumerated in the advisory, any instance that has not applied the security update for CVE‑2026‑58647 remains at risk.
Risk and Exploitability
The CVSS score of 8 indicates high severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector appears to be the web interface of the report server, requiring authorized access to inject and trigger malicious scripts, which could then be used to spoof user identities or data over the network.
OpenCVE Enrichment