First published: Tue Feb 11 2025(Updated: )
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server allows Authentication Bypass.This issue affects Tableau Server: from 2023.3 through 2023.3.5.
Credit: security@salesforce.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tableau Server | >=2023.3<=2023.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26494 is classified as a high severity vulnerability due to its potential for Authentication Bypass.
To fix CVE-2025-26494, update your Salesforce Tableau Server to version 2023.3.6 or later.
CVE-2025-26494 allows attackers to perform Server-Side Request Forgery, possibly leading to unauthorized access.
CVE-2025-26494 affects Salesforce Tableau Server versions from 2023.3 through 2023.3.5.
Currently, the recommended action is to upgrade to a secure version as no official workaround has been provided for CVE-2025-26494.