CVE-2025-52447: Tableau Server
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules) allows Interface Manipulation (data access to the production database cluster). This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Affected products
- Tableau Tableau Server: before 2023.3.19 (fixed in 2023.3.19); from 2024.2, before 2024.2.12 (fixed in 2024.2.12); from 2025.1, before 2025.1.3 (fixed in 2025.1.3)
Published 2025-07-25. Last modified 2026-06-17.