CVE-2025-26496 | Salesforce Tableau Server/Tableau Desktop up to 2023.3.18/2024.2.11/2025.1.2 File Upload type confusion (EUVD-2025-25627)
A vulnerability described as problematic has been identified in Salesforce Tableau Server and Tableau Desktop up to 2023.3.18/2024.2.11/2025.1.2. This affects an unknown part of the component File Upload Module. Such manipulation leads to type confusion.
This vulnerability is listed as CVE-2025-26496. The attack must be carried out from within the local network. There is no available exploit.
Upgrading the affected component is recommended.