CVE 9.6 CRITICAL

CVE-2025-26496_CVE-2025-26496

9.6 / 10
CRITICAL
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code Inclusion.This issue affects Tableau Server, Tableau Desktop: before 2025.1.3, before 2024.2.12, before 2023.3.19.

Basic Information

ID CVE-2025-26496
Source Salesforce
Published Aug 22, 2025 at 20:10
Modified Aug 22, 2025 at 20:43

Affected Product

Vendor Salesforce
Product Tableau Server, Tableau Desktop
Affected Versions Salesforce Tableau Server, Tableau Desktop 0
Salesforce Tableau Server, Tableau Desktop 0
Salesforce Tableau Server, Tableau Desktop 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.