Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code Inclusion.This issue affects Tableau Server, Tableau Desktop: before 2025.1.3, before 2024.2.12, before 2023.3.19.
History

Sat, 23 Aug 2025 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux
Microsoft
Microsoft windows
Salesforce
Salesforce tableau Desktop
Salesforce tableau Server
Tableau
Tableau tableau Desktop
Tableau tableau Server
Vendors & Products Linux
Linux linux
Microsoft
Microsoft windows
Salesforce
Salesforce tableau Desktop
Salesforce tableau Server
Tableau
Tableau tableau Desktop
Tableau tableau Server

Fri, 22 Aug 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 22 Aug 2025 20:30:00 +0000

Type Values Removed Values Added
Description Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code Inclusion.This issue affects Tableau Server, Tableau Desktop: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Weaknesses CWE-843
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Salesforce

Published:

Updated: 2025-08-22T20:43:14.344Z

Reserved: 2025-02-11T17:18:13.649Z

Link: CVE-2025-26496

cve-icon Vulnrichment

Updated: 2025-08-22T20:43:04.700Z

cve-icon NVD

Status : Received

Published: 2025-08-22T21:15:31.103

Modified: 2025-08-22T21:15:31.103

Link: CVE-2025-26496

cve-icon Redhat

No data.