PT-2026-40235 · Microsoft · Data Formulator

CVE-2026-41094

·

Published

2026-05-12

·

Updated

2026-05-16

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Data Formulator (affected versions not specified)
Description Improper control of code generation in the AI data visualization feature allows an unauthorized attacker to execute code over a network. This issue occurs when uploaded data is used to generate code, leading to remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06816
CVE-2026-41094

Affected Products

Data Formulator