Authorization Bypass in Salesforce Tableau Server for Windows and Linux
CVE-2025-52446

8HIGH

Key Information:

Vendor

Salesforce

Vendor
CVE Published:
25 July 2025

What is CVE-2025-52446?

An authorization bypass vulnerability in Salesforce Tableau Server on Windows and Linux environments affects specific versions of the product. This issue allows unauthorized users to manipulate interface data, potentially granting access to sensitive information in the production database cluster. It is imperative for users of versions before 2025.1.3, 2024.2.12, and 2023.3.19 to take preventive measures.

Affected Version(s)

Tableau Server Windows 0 < 2025.1.3

Tableau Server Windows 0 < 2024.2.12

Tableau Server Windows 0 < 2023.3.19

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52446 : Authorization Bypass in Salesforce Tableau Server for Windows and Linux