tableau CVE Vulnerabilities & Metrics

Focus on tableau vulnerabilities and metrics.

Last updated: 26 Nov 2025, 23:25 UTC

About tableau Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with tableau. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total tableau CVEs: 22
Earliest CVE date: 26 Aug 2019, 17:15 UTC
Latest CVE date: 22 Aug 2025, 21:15 UTC

Latest CVE reference: CVE-2025-52451

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 15

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical tableau CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.69

Max CVSS: 10.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 16
4.0-6.9 5
7.0-8.9 0
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS tableau CVEs

These are the five CVEs with the highest CVSS scores for tableau, sorted by severity first and recency.

All CVEs for tableau

CVE-2025-52451 tableau vulnerability CVSS: 0 22 Aug 2025, 21:15 UTC

Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) allows Absolute Path Traversal.This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

CVE-2025-52450 tableau vulnerability CVSS: 0 22 Aug 2025, 21:15 UTC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (abdoc api - create-data-source-from-file-upload modules) allows Absolute Path Traversal.This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

CVE-2025-26498 tableau vulnerability CVSS: 0 22 Aug 2025, 21:15 UTC

Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-connection-no-undo modules) allows Absolute Path Traversal.This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

CVE-2025-26497 tableau vulnerability CVSS: 0 22 Aug 2025, 21:15 UTC

Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Absolute Path Traversal.This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

CVE-2025-26496 tableau vulnerability CVSS: 0 22 Aug 2025, 21:15 UTC

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code Inclusion.This issue affects Tableau Server, Tableau Desktop: before 2025.1.3, before 2024.2.12, before 2023.3.19.

CVE-2025-52455 tableau vulnerability CVSS: 0 25 Jul 2025, 19:15 UTC

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

CVE-2025-52454 tableau vulnerability CVSS: 0 25 Jul 2025, 19:15 UTC

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

CVE-2025-52453 tableau vulnerability CVSS: 0 25 Jul 2025, 19:15 UTC

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

CVE-2025-52452 tableau vulnerability CVSS: 0 25 Jul 2025, 19:15 UTC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - duplicate-data-source modules) allows Absolute Path Traversal. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

CVE-2025-52449 tableau vulnerability CVSS: 0 25 Jul 2025, 19:15 UTC

Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) allows Alternative Execution Due to Deceptive Filenames (RCE). This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

CVE-2025-52448 tableau vulnerability CVSS: 0 25 Jul 2025, 19:15 UTC

Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allows Interface Manipulation (data access to the production database cluster). This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

CVE-2025-52447 tableau vulnerability CVSS: 0 25 Jul 2025, 19:15 UTC

Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules) allows Interface Manipulation (data access to the production database cluster). This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

CVE-2025-52446 tableau vulnerability CVSS: 0 25 Jul 2025, 19:15 UTC

Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface Manipulation (data access to the production database cluster).This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

CVE-2025-26495 tableau vulnerability CVSS: 0 11 Feb 2025, 18:15 UTC

Cleartext Storage of Sensitive Information vulnerability in Salesforce Tableau Server can record the Personal Access Token (PAT) into logging repositories.This issue affects Tableau Server: before 2022.1.3, before 2021.4.8, before 2021.3.13, before 2021.2.14, before 2021.1.16, before 2020.4.19.

CVE-2025-26494 tableau vulnerability CVSS: 0 11 Feb 2025, 18:15 UTC

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server allows Authentication Bypass.This issue affects Tableau Server: from 2023.3 through 2023.3.5.

CVE-2022-22128 tableau vulnerability CVSS: 0 17 Oct 2022, 16:15 UTC

Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only supports product versions for 24 months after release. Older versions have reached their End of Life and are no longer supported. They are also not assessed for potential security issues and do not receive security updates.

CVE-2022-22127 tableau vulnerability CVSS: 6.5 25 May 2022, 14:15 UTC

Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers using Local Identity Store for managing users. The vulnerability allows a malicious site administrator to change passwords for users in different sites hosted on the same Tableau Server, resulting in the potential for unauthorized access to data.Tableau Server versions affected are:2020.4.16, 2021.1.13, 2021.2.10, 2021.3.9, 2021.4.4 and earlierNote: All future releases of Tableau Server will address this security issue. Versions that are no longer supported are not tested and may be vulnerable.

CVE-2021-1629 tableau vulnerability CVSS: 5.8 26 Mar 2021, 17:15 UTC

Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.

CVE-2020-6939 tableau vulnerability CVSS: 10.0 23 Nov 2020, 17:15 UTC

Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated users. If exploited, this could allow a malicious user to configure Site-Specific SAML settings and could lead to account takeover for users of that site. Tableau Server versions affected on both Windows and Linux are: 2018.2 through 2018.2.27, 2018.3 through 2018.3.24, 2019.1 through 2019.1.22, 2019.2 through 2019.2.18, 2019.3 through 2019.3.14, 2019.4 through 2019.4.13, 2020.1 through 2020.1.10, 2020.2 through 2020.2.7, and 2020.3 through 2020.3.2.

CVE-2020-6938 tableau vulnerability CVSS: 5.0 08 Jul 2020, 16:15 UTC

A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow access to sensitive information in log files.

CVE-2019-19719 tableau vulnerability CVSS: 4.3 11 Dec 2019, 04:15 UTC

Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page.

CVE-2019-15637 tableau vulnerability CVSS: 5.5 26 Aug 2019, 17:15 UTC

Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.