CVE-2025-52454: Tableau Server

High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

Affected products

  • Tableau Tableau Server: before 2023.3.19 (fixed in 2023.3.19); from 2024.2, before 2024.2.12 (fixed in 2024.2.12); from 2025.1, before 2025.1.3 (fixed in 2025.1.3)

Published 2025-07-25. Last modified 2026-06-17.