CVE-2025-26496

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code Inclusion.This issue affects Tableau Server, Tableau Desktop: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*
cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*
cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*

History

04 Nov 2025, 15:48

Type Values Removed Values Added
CPE cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*
First Time Tableau tableau Server
Tableau
References () https://help.salesforce.com/s/articleView?id=005132575&type=1 - () https://help.salesforce.com/s/articleView?id=005132575&type=1 - Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2022-1364 - () https://www.cve.org/CVERecord?id=CVE-2022-1364 - Technical Description

Information

Published : 2025-08-22 21:15

Updated : 2025-11-04 15:48


NVD link : CVE-2025-26496

Mitre link : CVE-2025-26496

CVE.ORG link : CVE-2025-26496


JSON object : View

Products Affected

tableau

  • tableau_server
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')