CVE-2025-26495: Sensitive Data Exposure in Tableau Server
Cleartext Storage of Sensitive Information vulnerability in Salesforce Tableau Server can record the Personal Access Token (PAT) into logging repositories.This issue affects Tableau Server: before 2022.1.3, before 2021.4.8, before 2021.3.13, before 2021.2.14, before 2021.1.16, before 2020.4.19.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26495?
CVE-2025-26495 has been assigned a severity rating that indicates a critical risk due to the exposure of Personal Access Tokens in logs.
How do I fix CVE-2025-26495?
To fix CVE-2025-26495, upgrade your Salesforce Tableau Server to version 2022.1.3 or later, or to the latest available version.
What versions of Tableau Server are affected by CVE-2025-26495?
CVE-2025-26495 affects Tableau Server versions prior to 2022.1.3, 2021.4.8, 2021.3.13, 2021.2.14, 2021.1.16, and 2020.4.19.
What type of information is compromised in CVE-2025-26495?
CVE-2025-26495 compromises sensitive information by storing Personal Access Tokens in logging repositories in cleartext.
Is there a workaround for CVE-2025-26495?
Currently, the recommended action for CVE-2025-26495 is to upgrade to a secure version as there are no effective workarounds to mitigate the vulnerability.