CVE-2025-26496

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code Inclusion.This issue affects Tableau Server, Tableau Desktop: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Configurations

No configuration.

History

25 Aug 2025, 13:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.6
v2 : unknown
v3 : 9.3
Summary
  • (es) La vulnerabilidad de acceso a recursos mediante un tipo incompatible ('Confusión de tipos') en Salesforce Tableau Server, Tableau Desktop en Windows, Linux (módulos de carga de archivos) permite la inclusión de código local. Este problema afecta a Tableau Server, Tableau Desktop: antes de 2025.1.3, antes de 2024.2.12, antes de 2023.3.19.

22 Aug 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-22 21:15

Updated : 2025-08-25 20:24


NVD link : CVE-2025-26496

Mitre link : CVE-2025-26496

CVE.ORG link : CVE-2025-26496


JSON object : View

Products Affected

No product.

CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')