Video | Tableau | Tool strategy | Industry trends

LOG4J2 fix for All Tableau products - (Updated 15th December) see description for more

If you're on an older Tableau build, the Log4j2 vulnerability means you need to update or uninstall it right now.

Part ofBehind The Scenes
Watch on YouTube
  • Every Tableau product is affected by the Log4j2 remote code execution vulnerability, including Desktop, Public, Reader, Online, Server and Prep Builder across Windows, Mac and Linux.
  • You must be on the build released on 15th December 2021 to be patched, not just on 2020.4 generally; versions 2020.3 and older are past end of maintenance and will not be patched.
  • Tableau Prep treats every release as a patch, so your only fix is to upgrade to the latest version (2021.4.1), not stay on an older build.
  • Tableau's knowledge base offers manual mitigation steps, but they need admin rights and are hard to maintain, so updating is by far the easiest route.
  • Uninstall old versions entirely; leaving them on your laptop keeps you exposed, as a targeted workbook could compromise your machine and reach your server and data.

Every Tableau product is exposed to the Log4j2 remote code execution vulnerability, and the only reliable fix is updating to the specific patched build released on 15th December 2021, not just any recent version.

This covers Tableau Desktop, Public, Reader, Online, Server and Prep Builder across Windows, Mac and Linux, all of which use the affected Apache Log4j2 component. Tim recorded this as the situation was unfolding, so he flags that further patches may follow after this video.

The Breakdown
  • Every Tableau product is affected 1:23

    Log4j2 is embedded across Apache-based technology used throughout the Tableau product line, so the vulnerability isn't limited to Server or Online — Desktop, Public, Reader, Prep Builder and every OS build are all exposed.

  • Being on 2020.4 isn't enough 2:22

    You need the exact build released on 15th December 2021, not just 'the 2020.4 line' in general — check the specific release date on the download page before assuming you're covered.

  • Older versions past end of maintenance won't be patched 2:41

    2020.3 and earlier already had maintenance withdrawn, so Tableau isn't issuing a fix for them regardless of the vulnerability's severity — staying on those builds means staying exposed indefinitely.

  • Tableau Prep has its own versioning quirk 3:41

    Because every Prep release functions as a patch rather than a separate maintained branch, you can't wait for an older Prep version to be updated — 2021.4.1 is the only version with the fix, so upgrading is the only option.

  • Manual mitigation exists but is hard to sustain 5:24

    Tableau's knowledge base lists manual workaround steps (registry edits on Windows, terminal commands on Mac), but they require admin rights and are easy to get wrong or fall behind on — treat this as a stopgap, not a real alternative to updating.

  • Uninstall, don't just ignore, old installs 6:40

    Leaving an outdated version sitting on your machine keeps you exposed even if you never open it yourself — a specifically crafted workbook opened in that old version could compromise your laptop and, from there, your server and data.

Worth Knowing
  • This vulnerability was still evolving as the video was made — Tim notes a further Log4j2 issue emerged after this patch and points to the video description for updates.
  • Manual mitigation steps require admin rights (sudo on Mac, registry/directory changes on Windows), which most people in corporate environments won't have.
  • Version numbers and patch behaviour differ by product, so don't assume the same update logic applies to Desktop, Server and Prep uniformly.
Use It When

Reach for this the moment you're auditing what Tableau builds are running across your organisation or on your own laptop after a security advisory — check exact patch dates, not just major version numbers, and uninstall anything unpatched rather than leaving it dormant.

How this Rollup was made provenance & method

A Rollup is drafted by AI from the video's transcript, then reviewed and edited by Tim. Everything used to produce this one is listed below — the model, the exact prompt, and the source video — so the process is transparent and reproducible.

Transcription
On-device — NVIDIA Parakeet v3 for recent videos, OpenAI Whisper large-v3 for earlier ones. The transcript never leaves the machine or gets published.
Drafting
Claude Sonnet 5 in the cloud, from that transcript.
Prompt
The exact Rollup prompt (v2) — the full system prompt, unedited.
Source video
Watch on YouTube
Drafted
5 July 2026 at 09:38
Reviewed & edited
5 July 2026 at 09:41 · by Tim Ngwena

Model + prompt + video is everything you'd need to recreate a Rollup like this yourself. The one thing we don't share is the transcript.

Rights. The video and its transcript are the property of TN Media Ltd. Unauthorised use or download is prohibited. © TN Media Ltd.