CVE-2025-26498 | Salesforce Tableau Server up to 2023.3.18/2024.2.11/2025.1.2 establish-connection-no-undo unrestricted upload
A vulnerability has been found in Salesforce Tableau Server up to 2023.3.18/2024.2.11/2025.1.2 and classified as critical. Affected by this issue is some unknown functionality of the component establish-connection-no-undo. Performing manipulation results in unrestricted upload.
This vulnerability is known as CVE-2025-26498. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.