VYPR
High severity7.5NVD Advisory· Published Feb 11, 2025· Updated Jun 17, 2026

CVE-2025-26495

CVE-2025-26495

Description

Cleartext Storage of Sensitive Information vulnerability in Salesforce Tableau Server can record the Personal Access Token (PAT) into logging repositories.This issue affects Tableau Server: before 2022.1.3, before 2021.4.8, before 2021.3.13, before 2021.2.14, before 2021.1.16, before 2020.4.19.

Affected products

3
  • cpe:2.3:a:tableau:tableau_server:*:*:*:*:*:*:*:*
    Range: >=2020.4,<2020.4.19
  • Salesforce/Tableau Serverllm-fuzzy2 versions
    <2022.1.3, <2021.4.8, <2021.3.13, <2021.2.14, <2021.1.16, <2020.4.19+ 1 more
    • (no CPE)range: <2022.1.3, <2021.4.8, <2021.3.13, <2021.2.14, <2021.1.16, <2020.4.19
    • (no CPE)range: 0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.