Authorization Bypass Vulnerability in Tableau Server by Salesforce
CVE-2025-52448
What is CVE-2025-52448?
A serious vulnerability has been identified in Salesforce Tableau Server that allows unauthorized users to bypass access controls by manipulating user-controlled keys. This flaw affects various versions of Tableau Server prior to 2025.1.3, 2024.2.12, and 2023.3.19, potentially exposing sensitive data from the production database cluster. Administrators must take immediate action to secure their installations to prevent unauthorized access and ensure the integrity of their data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Tableau Server Windows 0 < 2025.1.3
Tableau Server Windows 0 < 2024.2.12
Tableau Server Windows 0 < 2023.3.19
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
