PT-2025-6374 · Tableau · Tableau Server

Published

2025-02-11

·

Updated

2025-10-29

·

CVE-2025-26495

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tableau Server versions prior to 2022.1.3 Tableau Server versions prior to 2021.4.8 Tableau Server versions prior to 2021.3.13 Tableau Server versions prior to 2021.2.14 Tableau Server versions prior to 2021.1.16 Tableau Server versions prior to 2020.4.19
Description The issue concerns the storage of sensitive information in plaintext in Salesforce Tableau Server, which can record the Personal Access Token (PAT) in logging repositories.
Recommendations For versions prior to 2022.1.3, update to version 2022.1.3 or later. For versions prior to 2021.4.8, update to version 2021.4.8 or later. For versions prior to 2021.3.13, update to version 2021.3.13 or later. For versions prior to 2021.2.14, update to version 2021.2.14 or later. For versions prior to 2021.1.16, update to version 2021.1.16 or later. For versions prior to 2020.4.19, update to version 2020.4.19 or later.

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-26495

Affected Products

Tableau Server