← Back

CVE-2025-26496

nvd nist
Published: Aug 22, 2025Modified: Nov 4, 2025

JSON object

Loading...
9.3
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.5 / Impact: 6.0
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code Inclusion.This issue affects Tableau Server, Tableau Desktop: before 2025.1.3, before 2024.2.12, before 2023.3.19.

Affected (3)

1 product
Tableau Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Tableau
Before 2023.3.19
From 2024.2 to 2024.2.12
From 2025.1 to 2025.1.3

References (2)

Source: security@salesforce.com
Vendor Advisory
Source: security@salesforce.com
Technical Description

Timeline

No history available yet.