CVE-2025-26496
published 2025-08-22CVE-2025-26496: Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload…
PriorityP350critical9.3CVSS 3.1
AVLACLPRNUINSCCHIHAH
EPSS
0.21%
10.9th percentile
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code Inclusion.This issue affects Tableau Server, Tableau Desktop: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tableau | tableau_server | < 2023.3.19 | 2023.3.19 |
| tableau | tableau_server | >= 2024.2 < 2024.2.12 | 2024.2.12 |
| tableau | tableau_server | >= 2025.1 < 2025.1.3 | 2025.1.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-22
Published