CVE-2025-26494: Server Side Request Forgery vulnerability in Tableau Server
Published Feb 11, 2025
·Updated
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server allows Authentication Bypass.This issue affects Tableau Server: from 2023.3 through 2023.3.5.
Affected Software
2 affected components
Salesforce Tableau Server>=2023.3<=2023.3.5
Tableau Tableau Server>=2023.3<=2023.3.5
Event History
Feb 11, 2025
CVE Published
via MITRE·05:33 PM
Data Sourced
via MITRE·05:33 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-26494?
CVE-2025-26494 is classified as a high severity vulnerability due to its potential for Authentication Bypass.
2
How do I fix CVE-2025-26494?
To fix CVE-2025-26494, update your Salesforce Tableau Server to version 2023.3.6 or later.
3
What impact does CVE-2025-26494 have on my Tableau Server?
CVE-2025-26494 allows attackers to perform Server-Side Request Forgery, possibly leading to unauthorized access.
4
Which versions of Tableau Server are affected by CVE-2025-26494?
CVE-2025-26494 affects Salesforce Tableau Server versions from 2023.3 through 2023.3.5.
5
Is there a workaround for CVE-2025-26494?
Currently, the recommended action is to upgrade to a secure version as no official workaround has been provided for CVE-2025-26494.