HomeSecurityTableau Server: Critical vulnerability allows system compromise

Tableau Server: Critical vulnerability allows system compromise

A critical security vulnerability in Tableau Server could allow attackers to upload and execute malicious files, potentially leading to a complete system compromise.

The vulnerability, which is tracked as CVE-2025-26496 (CVSS 9.6/10), affects multiple versions of both Tableau Server and Tableau Desktop on Windows and Linux platforms .

Tableau Server vulnerability

Tableau Server: Multiple vulnerabilities

Salesforce Security identified five vulnerabilities during a proactive security assessment. Fixes were released with the July 22, 2025 Maintenance Release . The most severe vulnerability, CVE-2025-26496, is a Type Confusion bug in the File Upload modules , allowing Local Code Inclusion attacks . The vulnerability affects Tableau Server versions before 2025.1.4, before 2024.2.13, and before 2023.3.20 .

See also: Apple vulnerability: PoC Exploit released for zero-day bug

This type of vulnerability occurs when the application incorrectly handles data types when processing files, potentially allowing attackers to bypass security checks and execute arbitrary code on the target system.

Other significant vulnerabilities include CVE-2025-26497 (CVSS 7.7) and CVE-2025-26498 (CVSS 7.7), which concern Uncontrolled File Upload, affecting the Flow Editor and establish-connection-no-undo respectively. These vulnerabilities allow Absolute Path Traversal, allowing attackers to write files to arbitrary locations on the server's file system.

The last two vulnerabilities in Tableau Server, tracked as CVE-2025-52450 and CVE-2025-52451 (path traversal), affect the create-data-source-from-file-upload modules of the tabdoc API. These vulnerabilities allow attackers to perform directory traversal attacks using malicious payloads to access sensitive system files outside the intended upload directory.

See also: Docker Desktop Windows: Vulnerability leads to system compromise

Tableau Server: Critical vulnerability allows system compromise

Improper input validation allows attackers to bypass path sanitization mechanisms through techniques such as double encoding (%252e%252e%252f) or Unicode normalization. The affected modules process user-supplied file paths without sufficient validation, potentially allowing attackers to replace critical system files, gain access to configuration data, or plant webshells for persistent access.

Danger and protection

In enterprise environments, these vulnerabilities could facilitate lateral movement and privilege escalation. Organizations running affected versions of Tableau Server should immediately upgrade to the latest supported maintenance release. The vulnerability disclosure follows responsible disclosure practices, with Salesforce providing fixes in advance of public disclosure.

System administrators should prioritize remediation due to the critical CVSS scores and the potential for remote code execution. The combination of file upload and path traversal vulnerabilities creates a dangerous attack channel that could lead to a complete server compromise, data extraction, and deployment of ransomware or other malicious payloads.

Security teams should also review access logs for suspicious activity, implement Web Application Firewall (WAF) rules, and conduct post-remediation security assessments to ensure there was no breach prior to remediation.

See also: GeoServer: Critical vulnerability allows remote code execution

Tableau Server: Critical vulnerability allows system compromise

The Tableau Server incident shows once again that applications that are considered “business tools” rather than traditional targets (such as web servers or VPN gateways) can become critical entry points for attacks. The more tools are integrated into the core of business operations, the more their value to attackers increases. Furthermore, the existence of multiple vulnerabilities in the same product highlights the perennial problem of “attack surface”: each new feature added to a platform can create new “doors” that need to be protected.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

From a strategic perspective, this highlights two points: first, that organizations cannot consider any software “secondary” when it comes to security; second, that true resilience comes not just from patches but from a culture of continuous monitoring, auditing, and risk assessment. Ultimately, such incidents are not just technical issues but business continuity issues, since a breach of critical data analytics tools can have a knock-on effect on decision-making, reliability, and customer and partner trust.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS