cbcvebase.
CVE-2025-26496
published 2025-08-22

CVE-2025-26496: Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload…

PriorityP350critical9.3CVSS 3.1
AVLACLPRNUINSCCHIHAH
EPSS
0.21%
10.9th percentile
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code Inclusion.This issue affects Tableau Server, Tableau Desktop: before 2025.1.3, before 2024.2.12, before 2023.3.19.

Affected

3 ranges
VendorProductVersion rangeFixed in
tableautableau_server< 2023.3.192023.3.19
tableautableau_server>= 2024.2 < 2024.2.122024.2.12
tableautableau_server>= 2025.1 < 2025.1.32025.1.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.