« Back to list

Microsoft

Microsoft Power BI Report Server: vulnerabilities and CVEs

Microsoft Power BI Report Server has 11 published vulnerabilities, 3 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs11
Last 12 months3
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-65811High (8.8)0.96%—Aug 11, 2026
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
CVE-2026-58647Medium (5.4)0.52%—Jul 14, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
CVE-2026-21229High (8.8)0.96%—Feb 10, 2026
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
CVE-2024-43612Medium (4.7)0.73%—Oct 8, 2024
Power BI Report Server Spoofing Vulnerability
CVE-2024-43481High (8.8)1.8%—Oct 8, 2024
Power BI Report Server Spoofing Vulnerability
CVE-2023-21806High (8.2)0.78%—Feb 14, 2023
Power BI Report Server Spoofing Vulnerability
CVE-2021-41372Critical (9.6)0.68%—Nov 10, 2021
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed…
CVE-2021-31984High (8.8)1.9%—Jul 14, 2021
Power BI Remote Code Execution Vulnerability
CVE-2021-26859Medium (6.5)3.4%—Mar 11, 2021
Microsoft Power BI Information Disclosure Vulnerability
CVE-2020-1173Medium (6.8)2.5%—May 21, 2020
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An authenticated attacker could exploit the vulnerability by uploading a specially…
CVE-2019-1332Medium (6.1)8.7%—Dec 10, 2019
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server…

Other products by Microsoft