What is the Salesforce GraphQL Exploit and What You Should Do
ID: f75e47ba-8ab1-51f0-8d3e-ae4d177d5ab3
STIX ID: report--f75e47ba-8ab1-51f0-8d3e-ae4d177d5ab3
Feed Name: Security Boulevard
Date Published: 2026-03-09
Date Updated: 2026-04-22
Author: Drew Gatchell, Sr. Director of Threat Detection, AppOmni
AppOmni details active campaigns exploiting overly permissive Salesforce Experience Cloud guest-user permissions via a GraphQL-based AuraInspector variant that can exfiltrate large volumes of CRM contact information; the post explains the exposure is due to misconfiguration (not a new Salesforce platform vulnerability), describes observed follow-on vishing and SaaS compromise risks, and outlines AppOmni's posture monitoring, new threat detection rule, remediation steps, and customer notifications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
