Skip to content
Breaking News
 2026-03-11 Meta turns to AI to sniff out scams on Facebook, Messenger and WhatsApp  2026-03-11 Meta Disables 150K Accounts Linked to Southeast Asia Scam Centers in Global Crackdown  2026-03-11 Labour scarcity is forcing IT leaders to rethink automation economics  2026-03-11 Why zero trust breaks down in IoT and OT environments  2026-03-11 What You Need to Know
  • Home

Cybernoz – Cybersecurity News

Search

Overly permissive ‘guest’ settings put Salesforce customers at risk

 Cybernoz  March 11, 2026  Posted in CISOOnline
Share: XFacebookPinterestRedditVKDiggLinkedinMix

According to the advisory, the campaign specifically targets environments where three conditions exist. These include instances with guest profiles having excessive object or field permissions, organization-wide default access for external users is not set to private, and guest users are allowed to access public APIs. These conditions allow attackers to query data through Experience Cloud guest profiles.

Why Salesforce environments make tempting targets

Salesforce deployments are particularly attractive because of the sensitive data they hold and the complexity of their access models.

“Salesforce instances often contain highly sensitive customer data, including credentials and secrets that can be used for lateral movement,” said Vincenzo Lozzo, CEO and cofounder of SlashID. At the same time, he added, the platform’s layered permissions architecture, including profiles, permissions sets, sharing rules, and integrations, which are not very well understood and can make accidental overexposure easy.



Source link

Related Articles

Critical flaw in HPE Aruba CX switches lets attackers seize admin control without credentials
Critical flaw in HPE Aruba CX switches lets attackers seize admin control without credentials
OAuth vulnerability in n8n automation platform could lead to system compromise
OAuth vulnerability in n8n automation platform could lead to system compromise
Targeted advertising is also targeting malware
Targeted advertising is also targeting malware
6 Mittel gegen Security-Tool-Wildwuchs
6 Mittel gegen Security-Tool-Wildwuchs

Post navigation

OPSWAT debuts MetaDefender Aether combining sandboxing, ML scoring and threat hunting for perimeter security →
← Intigriti collaborates with PortSwigger to support ethical hacking excellence

Latest Posts

  • Meta turns to AI to sniff out scams on Facebook, Messenger and WhatsApp
  • Meta Disables 150K Accounts Linked to Southeast Asia Scam Centers in Global Crackdown
  • Labour scarcity is forcing IT leaders to rethink automation economics
  • Why zero trust breaks down in IoT and OT environments
  • What You Need to Know

Copyright © 2026 Cybernoz - Cybersecurity News

Design by ThemesDNA.com