Skip to main content

Vendor/product archive

tableau / tableau_server CVEs

Beta · best-effort

22 CVEs tagged to tableau / tableau_server3 Critical, 15 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2025-26498

Published Aug 22, 2025

Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-connection-no-undo modules) allows Absolute Path Traversal.…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-26496

Published Aug 22, 2025

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-26495

Published Feb 11, 2025

Cleartext Storage of Sensitive Information vulnerability in Salesforce Tableau Server can record the Personal Access Token (PAT) into logging repositories.This issue affects Table…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-26494

Published Feb 11, 2025

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server allows Authentication Bypass.This issue affects Tableau Server: from 2023.3 through 2023.3.5.

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-22128

Published Oct 17, 2022

Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau onl…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-22127

Published May 25, 2022

Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers using Local Identity Store for managing users. The vulnerabi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6939

Published Nov 23, 2020

Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated users. If exploited, this could allow a malicious user to config…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1