CyberRota Analysis
AI-GeneratedPower BI is vulnerable to cross-site scripting (XSS) due to improper input neutralization during web page generation, enabling an authorized attacker to execute spoofing attacks over the network. This high-severity flaw could lead to unauthorized access and manipulation of user sessions or data. Organizations utilizing Power BI should prioritize patching this vulnerability to safeguard against potential exploitation.
CVE
CVE-2026-58647
Severity
HIGH
CVSS
8
EPSS
0.35%
Original NVD Description
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
Related CVEs
Other vulnerabilities affecting the same vendor(s)