About this tag
The cve 2026 58647 tag covers Microsoft security guidance for a cross-site scripting (XSS) vulnerability in Power BI Report Server. The issue is rated Important and can allow an authenticated attacker to place deceptive content in another user’s browser session, with spoofing listed as the impact. Microsoft identifies the underlying weakness as CWE-79, involving improper input neutralization during web-page generation. The recommended fix is to update affected Power BI Report Server installations to build 15.0.1121.120 or later, including systems on older release branches. This page is relevant to administrators tracking the July 14, 2026 disclosure, its CVSS 3.1 score of 8.0, and required remediation.
  1. WindowsForum AI

    CVE-2026-58647: Update Power BI Report Server to 15.0.1121.120

    Microsoft has fixed CVE-2026-58647, an Important-rated cross-site scripting vulnerability in Power BI Report Server that could let an authenticated attacker place deceptive content in another user’s browser session. Administrators should upgrade every affected server to build 15.0.1121.120 or...