Impact
Microsoft Power BI Report Server suffers from a lack of proper input validation that allows an attacker who has authenticated to the server to execute arbitrary code. The vulnerability is tied to CWE‑20 and enables remote execution, potentially compromising any data stored or processed by the instance.
Affected Systems
The affected product is Microsoft Power BI Report Server. No specific versions are disclosed in the advisory; users should verify whether their instance is impacted by consulting the Microsoft Security Advisory linked in the references.
Risk and Exploitability
The CVSS score of 8.8 marks this issue as high severity, and the EPSS score is not available, but the risk remains significant because the exploit requires network access to a fully authenticated instance. Since the vulnerability is not listed in the CISA KEV catalog, it has not yet appeared in a known exploitation campaign, yet the potential damage from remote code execution warrants immediate attention.
OpenCVE Enrichment