SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-58647

HIGH · CVSS 8 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Power BI is vulnerable to cross-site scripting (XSS) due to improper input neutralization during web page generation, enabling an authorized attacker to execute spoofing attacks over the network. This high-severity flaw could lead to unauthorized access and manipulation of user sessions or data. Organizations utilizing Power BI should prioritize patching this vulnerability to safeguard against potential exploitation.

CVE
CVE-2026-58647
Severity
HIGH
CVSS
8
EPSS
0.35%

Original NVD Description

Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)