logo

What is the Salesforce GraphQL Exploit and What You Should Do

ID: f75e47ba-8ab1-51f0-8d3e-ae4d177d5ab3

STIX ID: report--f75e47ba-8ab1-51f0-8d3e-ae4d177d5ab3

Feed Name: Security Boulevard

Threat Score
65/100

Date Published: 2026-03-09

Date Updated: 2026-04-22

Author: Drew Gatchell, Sr. Director of Threat Detection, AppOmni

...
...

AppOmni details active campaigns exploiting overly permissive Salesforce Experience Cloud guest-user permissions via a GraphQL-based AuraInspector variant that can exfiltrate large volumes of CRM contact information; the post explains the exposure is due to misconfiguration (not a new Salesforce platform vulnerability), describes observed follow-on vishing and SaaS compromise risks, and outlines AppOmni's posture monitoring, new threat detection rule, remediation steps, and customer notifications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.