Salesforce Security identified and resolved multiple vulnerabilities in Tableau Server as part of a proactive security assessment. Fixes for these issues were included in the July Maintenance Release, published on July 22, 2025.
The vulnerabilities included:
Access of Resource Using Incompatible Type ('Type Confusion')
Unrestricted Upload of File with Dangerous Type
Improper Limitation of a Pathname to a Restricted Directory
Improper Input Validation
This issue affects Tableau Server versions: before 2025.1.3, before 2024.2.12, before 2023.3.19.
All Tableau Server customers are strongly advised to upgrade to the most recent supported version. More information on each vulnerability is provided below.
CVE-2025-26496 - Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server & Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code Inclusion. This issue affects Tableau Server & Tableau Desktop: before 2025.1.4, before 2024.2.13, before 2023.3.20
CVSSv3 Score: 9.6
CVE-2025-26497- Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Absolute Path Traversal. This issue affects Tableau Server: before 2025.1.4, before 2024.2.13, before 2023.3.20. CVSSv3 Score: 7.7
CVE-2025-26498 - Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-connection-no-undo modules) allows Absolute Path Traversal. This issue affects Tableau Server: before 2025.1.4, before 2024.2.13, before 2023.3.20. CVSSv3 Score: 7.7
CVE-2025-52450 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) allows Absolute Path Traversal. This issue affects Tableau Server: before 2025.1.4, before 2024.2.13, before 2023.3.20. CVSSv3 Score: 8.5
CVE-2025-52451 - Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) allows Absolute Path Traversal. This issue affects Tableau Server: before 2025.1.4, before 2024.2.13, before 2023.3.20. CVSSv3 Score: 8.5
Customers should:
005132575

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.