CVE-2025-26497: Malicious File Upload
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Absolute Path Traversal.This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26497?
CVE-2025-26497 is classified as a high-severity vulnerability due to its potential for absolute path traversal and unrestricted file uploads.
How do I fix CVE-2025-26497?
To mitigate CVE-2025-26497, upgrade Tableau Server to version 2025.1.3, 2024.2.12, or 2023.3.19 or later.
What versions of Tableau Server are affected by CVE-2025-26497?
CVE-2025-26497 affects Tableau Server versions prior to 2025.1.3, 2024.2.12, and 2023.3.19.
What impact can CVE-2025-26497 have on my system?
CVE-2025-26497 can allow attackers to upload dangerous files leading to potential system compromise.
Can CVE-2025-26497 be exploited remotely?
Yes, CVE-2025-26497 can be exploited remotely by unauthorized users if left unpatched.