Critical Salesforce Tableau Vulnerabilities Let Attackers Execute Code Remotely

The vulnerabilities, revealed through a security advisory published on June 26, 2025, impact Tableau Server versions before 2025.1.3, before 2024.2.12, and before 2023.3.19, prompting urgent calls for immediate patching across enterprise environments. Three additional authorization bypass vulnerabilities (CVE-2025-52446, CVE-2025-52447, and CVE-2025-52448), each scoring 8.0 on the CVSS scale, affect the tab-doc API modules, set-initial-sql tabdoc command modules, and validate-initial-sql API modules, respectively. These vulnerabilities exploit user-controlled keys to manipulate interfaces, granting unauthorized access to production database clusters containing sensitive organizational data. This flaw enables Remote Code Execution (RCE) through alternative execution methods due to deceptive filenames, potentially allowing attackers to gain complete system control. These vulnerabilities enable resource location spoofing, allowing attackers to manipulate server requests and potentially access internal systems. This improper limitation of pathname restrictions enables absolute path traversal attacks, potentially exposing sensitive files across the server filesystem through directory traversal techniques. The most severe vulnerability, CVE-2025-52449, carries a CVSS 3.1 base score of 8.5 and originates from unrestricted file upload capabilities within the Extensible Protocol Service modules. Enables remote code execution and unauthorized database access. Additionally, customers utilizing Trino (formerly Presto) drivers must update to the most recent driver version to ensure comprehensive protection. Salesforce strongly advises all Tableau Server customers to implement immediate remediation measures.

This Cyber News was published on cybersecuritynews.com. Publication date: Mon, 28 Jul 2025 06:10:24 +0000


Cyber News related to Critical Salesforce Tableau Vulnerabilities Let Attackers Execute Code Remotely

Salesforce Lays-Off 700 Staff - American CRM giant Salesforce is reportedly reducing its workforce again, on top of a sizeable reduction back in 2023. The Wall Street Journal reported that Salesforce is laying off 700 workers, or 1 percent of its workforce, in the latest round of ...
1 year ago Silicon.co.uk
Inside the strategy of Salesforce's new Chief Trust Officer - In this Help Net Security interview, Arkin discusses a collaborative approach to building trust among customers, employees, and stakeholders, focusing on transparency, shared responsibility, and empowering others to integrate trusted and responsible ...
1 year ago Helpnetsecurity.com
CVE-2022-22127 - Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers using Local Identity Store for managing users. The vulnerability allows a malicious site administrator to change passwords for ...
2 years ago
Critical Salesforce Tableau Vulnerabilities Let Attackers Execute Code Remotely - The vulnerabilities, revealed through a security advisory published on June 26, 2025, impact Tableau Server versions before 2025.1.3, before 2024.2.12, and before 2023.3.19, prompting urgent calls for immediate patching across enterprise ...
4 months ago Cybersecuritynews.com CVE-2025-52446
Tableau Server Vulnerability Exposes Sensitive Data to Attackers - A critical vulnerability has been discovered in Tableau Server, a widely used data visualization platform, which could allow attackers to access sensitive data. This security flaw, identified as CVE-2024-12345, enables unauthorized users to bypass ...
3 months ago Cybersecuritynews.com CVE-2024-12345
Salesforce Attacks: Latest Threats and Security Measures - Salesforce, a leading customer relationship management platform, has increasingly become a target for cyber attackers. This article delves into the latest Salesforce attacks, highlighting the methods threat actors use to exploit vulnerabilities and ...
2 months ago Cybersecuritynews.com CVE-2023-34362 CVE-2023-34363 UNC2452
ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH - A wave of data breaches impacting companies like Qantas, Allianz Life, LVMH, and Adidas has been linked to the ShinyHunters extortion group, which has been using voice phishing attacks to steal data from Salesforce CRM instances. These breaches have ...
3 months ago Bleepingcomputer.com Hunters Scattered Spider
Salesforce Releases Forensic Investigation Guide - Salesforce has published a comprehensive Forensic Investigation Guide aimed at helping organizations effectively investigate security incidents within their Salesforce environments. This guide provides detailed methodologies, best practices, and ...
2 months ago Cybersecuritynews.com
CVE-2019-15637 - Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop. ...
3 years ago
CVE-2025-26496 - Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code Inclusion.This issue affects Tableau Server, Tableau Desktop: ...
3 months ago
Allianz Life confirms data breach impacts majority of 1.4 million customers - ShinyHunters is a group of threat actors who are linked to multiple high-profile data breaches and attacks, including those against PowerSchool and the SnowFlake attacks, which ...
4 months ago Bleepingcomputer.com Hunters
CVE-2017-5178 - An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonderware Intelligence Versions 2014R3 and prior. These versions contain a system account that is installed by default. The default system account is ...
4 years ago
ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks - In a significant cybersecurity incident, the hacking group ShinyHunters has claimed responsibility for stealing 1.5 billion Salesforce records through breaches involving the company Drift. This massive data breach highlights the increasing risks ...
2 months ago Bleepingcomputer.com ShinyHunters
FBI Warns of Threat Actors Targeting Salesforce Customers - The FBI has issued a warning about threat actors targeting Salesforce customers through sophisticated cyberattacks. These threat actors exploit vulnerabilities and use social engineering tactics to gain unauthorized access to Salesforce environments, ...
2 months ago Darkreading.com
Scattered Lapsus Hunters Returns With Salesforce Leak Site - The Lapsus$ hacking group, known for its high-profile cyberattacks, has resurfaced with a new leak site targeting Salesforce, a major cloud software company. This resurgence follows a period of inactivity and signals a renewed threat to enterprise ...
1 month ago Darkreading.com Lapsus$
The Biggest Tech Talent Gap Can Be Found in the SAP Ecosystem - They're not just looking for people who can write code; they want individuals who can implement, integrate, and run a variety of software platforms crucial for modern businesses. A recent Forbes case study explored dynamic areas like cybersecurity, ...
1 year ago Cysecurity.news
Salesforce deepens AI ties with OpenAI, Anthropic to power AgentForce platform in 2025 - Salesforce has announced a strategic expansion of its AI partnerships with leading firms OpenAI and Anthropic to enhance its AgentForce platform, set to launch in 2025. This collaboration aims to integrate advanced AI capabilities into Salesforce's ...
1 month ago Reuters.com
ShinyHunters starts leaking data stolen in Salesforce attacks - ShinyHunters, a notorious cybercriminal group, has begun leaking data stolen from recent Salesforce attacks. This development marks a significant escalation in the ongoing cyber threats targeting major cloud service providers. The leaked data ...
1 month ago Bleepingcomputer.com ShinyHunters
Critical Flaw in Salesforce AgentForce Extension Exposes Data to Attackers - A critical security vulnerability has been discovered in the Salesforce AgentForce browser extension, which is widely used by customer service teams to enhance productivity. This flaw could allow attackers to access sensitive customer data and ...
2 months ago Infosecurity-magazine.com
SalesLoft March GitHub repo breach led to Salesforce data theft attacks - In March 2024, SalesLoft experienced a significant security breach when attackers accessed a GitHub repository, leading to a data theft incident targeting Salesforce customers. The breach exposed sensitive information that threat actors leveraged to ...
2 months ago Bleepingcomputer.com
Salesloft breached to steal OAuth tokens for Salesforce data theft attacks - Salesloft, a sales engagement platform, suffered a security breach where attackers stole OAuth tokens to access Salesforce data. This incident highlights the increasing risks associated with OAuth token theft, which can lead to unauthorized access to ...
3 months ago Bleepingcomputer.com
FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data - The FBI has issued a warning about two advanced hacking groups, UNC6040 and UNC6395, actively targeting Salesforce data. These threat actors are exploiting vulnerabilities and using sophisticated tactics to infiltrate organizations and steal ...
2 months ago Bleepingcomputer.com UNC6040 UNC6395
Data theft campaign targets Salesforce users with malicious Excel files - A recent data theft campaign has been targeting Salesforce users by distributing malicious Excel files designed to steal sensitive information. The attackers leverage social engineering tactics to trick victims into opening these files, which then ...
3 months ago Infosecurity-magazine.com