Authorization Bypass Vulnerability in Tableau Server by Salesforce
CVE-2025-52448

8.1HIGH

Key Information:

Vendor

Salesforce

Vendor
CVE Published:
25 July 2025

What is CVE-2025-52448?

A serious vulnerability has been identified in Salesforce Tableau Server that allows unauthorized users to bypass access controls by manipulating user-controlled keys. This flaw affects various versions of Tableau Server prior to 2025.1.3, 2024.2.12, and 2023.3.19, potentially exposing sensitive data from the production database cluster. Administrators must take immediate action to secure their installations to prevent unauthorized access and ensure the integrity of their data.

Affected Version(s)

Tableau Server Windows 0 < 2025.1.3

Tableau Server Windows 0 < 2024.2.12

Tableau Server Windows 0 < 2023.3.19

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52448 : Authorization Bypass Vulnerability in Tableau Server by Salesforce