Authorization Bypass Vulnerability in Tableau Server by Salesforce
CVE-2025-52448
8.1HIGH
What is CVE-2025-52448?
A serious vulnerability has been identified in Salesforce Tableau Server that allows unauthorized users to bypass access controls by manipulating user-controlled keys. This flaw affects various versions of Tableau Server prior to 2025.1.3, 2024.2.12, and 2023.3.19, potentially exposing sensitive data from the production database cluster. Administrators must take immediate action to secure their installations to prevent unauthorized access and ensure the integrity of their data.
Affected Version(s)
Tableau Server Windows 0 < 2025.1.3
Tableau Server Windows 0 < 2024.2.12
Tableau Server Windows 0 < 2023.3.19