
Our team discovered a vulnerability in Salesforce Marketing Cloud that allowed us to leak PII of subscribers and emails sent through SFMC, without any auth. Assigned CVE-2026-22585, CVE-2026-22586, CVE-2026-22582, CVE-2026-22583, CVE-2026-2298. Read our writeup here: https://slcyber.io/research-center/ghosts-of-encryption-past-salesforce-exacttarget/
Post summary
A team reports an authentication bypass in Salesforce Marketing Cloud that leaks subscriber PII and emails, assigns several CVEs, and links to a writeup but provides no exploit code or active exploitation evidence.
