CVE Tools

Tableau

13 CVEs tracked since 2025. Since Jul 2025, none of them reached CISA KEV.

Tableau CVEs per month

Jul 2025 to Aug 2025. Point at a month, or focus the strip and use the arrow keys.
Tableau CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-0780
2025-0850

Products

The products that kept showing up in Tableau's monthly top three, with their CVEs summed over those months.

  1. Tableau Server132 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Tableau.

  1. CVE-2025-52451Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) allows Absolute Path Traversal.This issue affects T...8.5
  2. CVE-2025-52450Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (abdoc api - create-data-source-from-file-upload modules)...6.5
  3. CVE-2025-26498Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-connection-no-undo modules) allows Absolute Path Traversal.This issue affects...7.3
  4. CVE-2025-26497Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Absolute Path Traversal.This issue affects Tableau Server: ...7.3
  5. CVE-2025-26496Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code Inclusion.This is...9.3
  6. CVE-2025-52455Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 202...5.3
  7. CVE-2025-52454Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Location Spoofing. This issue affects Tableau Server: b...5.3
  8. CVE-2025-52453Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Location Spoofing. This issue affects Tableau Server: befo...8.2
  9. CVE-2025-52452Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - duplicate-data-source modules) allows Absol...8.5
  10. CVE-2025-52449Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) allows Alternative Execution Due to Deceptive File...8.5
  11. CVE-2025-52448Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allows Interface Manipulation (data access to the pr...8.1
  12. CVE-2025-52447Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules) allows Interface Manipulation (data access to ...8.1
  13. CVE-2025-52446Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface Manipulation (data access to the production data...8.0
  14. CVE-2025-26495Sensitive Data Exposure in Tableau Server7.5
  15. CVE-2025-26494Server Side Request Forgery vulnerability in Tableau Server7.7

The record

Peak rank
#126 in Jul 2025
Busiest month shown
Jul 2025, 8 CVEs
Months with a KEV entry
0 since Jul 2025
Monthly snapshots
2 since 2025
Tableau's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store