CVE-2021-26859 is an information disclosure vulnerability affecting Microsoft Power BI Report Server. With a CVSS score of 7.7 (HIGH), it allows an authenticated attacker to remotely access sensitive information with low attack complexity. While not currently listed in CISA KEV and lacking public exploit code, its FAUCET Risk Score of 64/100 indicates a notable risk. Community discussion and media coverage are limited, with only one article mentioning it as part of Microsoft's March 2021 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.0.1103.234CPE matchmatch criteria | cpe:2.3:a:microsoft:power_bi_report_server:15.0.1103.234:*:*:*:*:*:*:* | ||
15.0.1104.300CPE matchmatch criteria | cpe:2.3:a:microsoft:power_bi_report_server:15.0.1104.300:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.