CVE-2025-26494
Published: 11 February 2025
Description
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Security Summary
CVE-2025-26494 is a Server-Side Request Forgery (SSRF) vulnerability, classified as CWE-918, in Salesforce Tableau Server that allows authentication bypass. It affects Tableau Server versions from 2023.3 through 2023.3.5. The vulnerability carries a CVSS v3.1 base score of 7.7 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N) and was published on 2025-02-11T18:15:47.060.
An attacker requires low privileges (PR:L) to exploit this issue over the network (AV:N) with low attack complexity (AC:L) and no user interaction (UI:N). Successful exploitation changes scope (S:C) and results in high confidentiality impact (C:H) with no impact on integrity or availability, enabling authentication bypass via SSRF.
The Salesforce security advisory at https://help.salesforce.com/s/articleView?id=001534936&type=1 provides details on mitigation and patches.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
SSRF vulnerability in public-facing Tableau Server directly enables exploitation for authentication bypass.