Misconfigured Custom Salesforce Apps Expose Corporate Data
ID: b12c3e41-0047-54c9-9135-f24bb50b6579
STIX ID: report--b12c3e41-0047-54c9-9135-f24bb50b6579
Feed Name: Dark Reading
Security researchers at Varonis warn that common Apex misconfigurations and programming errors in Salesforce—notably using 'without sharing' Apex classes and lax permissions for guest/external users—have led to data leaks, credential exposure, and the ability to alter records across government and corporate instances. The advisory highlights how Apex can run with elevated privileges that bypass user access controls (enabling IDOR/BOLA and injection risks), references prior research showing widespread leaks, and recommends prioritizing security reviews, least-privilege access, input validation, and developer training to remediate and prevent further exposures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
