ACEN MDR Threat Alert – Tableau Server & Desktop – (CVE-2025-26496, CVSS 9.6/10)

On the 22nd of August 2025, a critical vulnerability (CVE-2025-26496, CVSS 9.6/10) was disclosed affecting Salesforce Tableau Server and Tableau Desktop across Windows and Linux platforms.

The flaw allows attackers on the same network segment to upload specially crafted files and achieve arbitrary code execution with no privileges or user interaction required. Here’s how to protect your environment and how ACEN supports affected clients.

What’s going on?

⚠️ CVE-2025-26496 is a Type Confusion vulnerability in the File Upload modules of Tableau products.

⚠️ Attackers can exploit the flaw via Local Code Inclusion, using malicious file uploads to execute arbitrary code.

⚠️ The vulnerability is exploitable from adjacent networks and can lead to complete system compromise.

Affected versions & mitigation

Product

Affected Versions

Fixed Version

Tableau Server & Desktop

Before 2025.1.3
Before 2024.2.12
Before 2023.3.19

Apply latest updates from Salesforce

Mitigation guidance:

  1. Immediately update Tableau to a secure version
  2. Segment networks to restrict adjacent access
  3. Monitor upload directories and logs
  4. Enforce least privilege on file upload modules
  5. Review installations with a security assessment

Why is this a problem?

  • This vulnerability is especially dangerous due to:
    • No authentication or user interaction required
    • Adjacent network attack vector
    • High potential for remote code execution
    • Impact on confidentiality, integrity, and availability
  • Attackers could gain access to sensitive systems, deploy malware, and maintain persistence across compromised hosts.

How does ACEN protect its customers?

If you’re using ACEN’s Extended Detection and Response (XDR) solution, it is designed to block many types of exploitation attempts that occur after the initial compromise. This enables our teams to stop threats and launch an investigation.

ACEN’s MDR service also deploys tailored detection scenarios that monitor system logs from Windows, firewalls, Microsoft 365, and other sources to identify and stop threat actors.

In the event of a serious incident, our Computer Security Incident Response Team (CSIRT) is available to provide expert support and guidance.

We continue to emphasize the importance of proactive security measures. Please ensure your systems are updated with the latest patches and configurations.

What can you do to mitigate the attack?

✅ Apply the latest Tableau patches immediately
✅ Review upload permissions and logs
✅ Isolate Tableau environments from high-risk network segments
✅ Audit your Tableau deployments for misconfigurations or legacy versions

But what if you can’t?

🛡️ Restrict access to the upload functionality via firewall and access control
🛡️ Monitor for suspicious file upload activity
🛡️ Temporarily disable external upload functions if possible

Need help to mitigate the risks?

Get in contact with Ken Van Hasselt today!

Share this article

Interested in learning more about our solutions and how they can benefit your business?

Contact us now for personalized insights and solutions.

Related articles

Keys layed out in the bacckground with the Qilin logo and some red-orange warning signs.

Qilin Ransomware: Why Belgian organisations need more than just prevention

Qilin ransomware is growing rapidly in Belgium. Learn why organisations need more than prevention...
Photo of the PAM team in the office, during a meeting.

SSH keys: Why your strongest security controls are a ticking timebomb

Unmanaged SSH keys are a major security risk. Learn how SSH certificates and Certificate...
Flag of the Netherlands with the NIS2 logo peeking from behind.

Dutch Cybersecurity Act: Insights from Belgium’s NIS2 journey

Get your organisation ready for the Dutch Cybersecurity Act 2026 with lessons learned from...

Subscribe to our newsletter

We only use your e-mail address to send newsletters.

We do not pass on your address to third parties.

Security as a Service

Experience peace of mind with our Security as a Service – your company’s ultimate shield against threats, featuring reliable 24/7 protection, local support, and a tailored approach to meet all your unique security needs.

We are looking for talent

Check out our careers platform and discover our wide range of cybersecurity opportunities!