CVE-2025-52449HIGH 8.5EPSS p13.8%
CVE-2025-52449CVE-2025-52449
Description
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) allows Alternative Execution Due to Deceptive Filenames (RCE). This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Scoring
| CVSS 3.1 | 8.5 (HIGH) |
| Vector | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
| EPSS | 0.23% probability of exploitation · percentile 13.8% · 2026-06-18T12:00:27Z |
| Published | 2025-07-25 |
| Last modified | 2025-10-31 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Unrestricted Upload of File with Dangerous Typecwe-434 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.