logo

Salesforce tags 5 CVEs after SaaS security probe uncovers misconfig risks

ID: 3c604a70-441c-503b-9e41-948a609c3822

STIX ID: report--3c604a70-441c-503b-9e41-948a609c3822

Feed Name: The Register (Security)

Threat Score
60/100

Date Published: 2025-06-11

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Salesforce assigned five CVEs after a researcher found over 20 configuration weaknesses in industry-cloud components (Flexcards, Data Mappers, etc.), with flaws that can expose encrypted field data, bypass permission checks, return plaintext of encrypted data, and allow guest access to settings; additional misconfigurations affecting Integration procedures, Data Packs, OmniOut, and OmniScript Saved Sessions were reported and left for customers to remediate. The report stresses that default/usable settings created these risks and recommends enforcing field-level security, tightening component permissions, applying updates, and avoiding public caching to prevent unauthorized access, credential leaks, and session data exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.