CVE-2025-52450: Tableau Server
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (abdoc api - create-data-source-from-file-upload modules) allows Absolute Path Traversal.This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Affected products
- Tableau Tableau Server: before 2023.3.19 (fixed in 2023.3.19); from 2024.2, before 2024.2.12 (fixed in 2024.2.12); from 2025.1, before 2025.1.3 (fixed in 2025.1.3)
Published 2025-08-22. Last modified 2026-06-17.