power_bi_report_server vulnerabilities
CVEs whose affected-version data names the power_bi_report_server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-65811High· 8.8Power BI Remote Code Execution Vulnerability
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
▾ TwilightMicrosoft · Power BI Report ServerEPSS 0.53%via CVEORG
CVE-2026-58647High· 8.0Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
▾ Twilightmicrosoft · power_bi_report_serverEPSS 0.35%via NVD
CVE-2021-31984High· 7.6Power BI Remote Code Execution Vulnerability
Power BI Remote Code Execution Vulnerability
▾ Twilightmicrosoft · power_bi_report_serverEPSS 1.9%via NVD