LiveActive security incident?Get immediate response
CVE Record

CVE-2020-6939: Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthen...

Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated users. If exploited, this could allow a malicious user to configure Site-Specific SAML settings and could lead to account takeover for users of that site. Tableau Server versions affected on both Windows and Linux are: 2018.2 through 2018.2.27, 2018.3 through 2018.3.24, 2019.1 through 2019.1.22, 2019.2 through 2019.2.18, 2019.3 through 2019.3.14, 2019.4 through 2019.4.13, 2020.1 through 2020.1.10, 2020.2 through 2020.2.7, and 2020.3 through 2020.3.2.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

This flaw affects some Tableau Server deployments using Site-Specific SAML. An unauthenticated user could use APIs to change SAML settings for a site, potentially enabling account takeover for that site. Treat it as serious where Tableau supports sensitive reporting, identity, or executive data access.

Executive priority

High priority for organizations using Tableau Server with SAML, especially if Tableau contains sensitive business data or is reachable beyond trusted networks. Schedule remediation promptly, but validate applicability first because the flaw is configuration-dependent.

Technical view

CVE-2020-6939 is a Tableau Server Site-Specific SAML authorization flaw. The source states affected Windows and Linux versions may allow unauthenticated API use to configure Site-Specific SAML settings, creating a potential site-level account takeover path.

Likely exposure

Exposure is limited to Tableau Server versions listed in the CVE, on Windows or Linux, where Site-Specific SAML is configured. Internet-facing Tableau instances or environments with broad network reach increase business risk.

Exploitation context

The bundle does not cite active exploitation, public exploit code, KEV listing, CVSS, or CWE data. Impact is still material because the described outcome is unauthenticated SAML configuration change and possible account takeover.

Researcher notes

The source bundle provides affected version ranges and impact, but lacks CVSS, CWE, exploit telemetry, and named fixed releases. Validation should focus on version range, Site-Specific SAML usage, API exposure, and evidence of unauthorized SAML configuration changes.

Mitigation direction

  • Check Salesforce/Tableau advisory for fixed versions and vendor remediation guidance.
  • Inventory Tableau Server deployments and compare versions against the affected ranges.
  • Prioritize upgrade or vendor-approved remediation for Site-Specific SAML deployments.
  • Restrict network access to Tableau administration and APIs until remediation is complete.
  • Review identity-provider trust settings after remediation for unauthorized SAML changes.

Validation and detection

  • Confirm Tableau Server version and operating system for every deployment.
  • Determine whether Site-Specific SAML is enabled for any site.
  • Review Tableau audit logs for unexpected SAML configuration changes.
  • Check access logs for unauthenticated requests tied to administrative or SAML configuration activity.
  • After remediation, verify unauthenticated users cannot change Site-Specific SAML settings.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2020-6939 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/aTableau Serverversions affected on both Windows and Linux are: 2018.2 through 2018.2.27, 2018.3 through 2018.3.24, 2019.1 through 2019.1.22, 2019.2 through 2019.2.18, 2019.3 through 2019.3.14, 2019.4 through 2019.4.13, 2020.1 through 2020.1.10, 2020.2 through 2020.2.7, 2020.3 through 2020.3.2Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.