CVE-2026-22583Disclosure(salesforce / marketing_cloud_engagement)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (CloudPagesUrl module) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • marketing_cloud_engagement

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-04); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
marketing_cloud_engagement

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-04: 1Mentions · 2026-05-05: 1Technical Details · 2026-02-04: 102-0405-05
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Assetnote@assetnote
    Disclosure

    Our team discovered a vulnerability in Salesforce Marketing Cloud that allowed us to leak PII of subscribers and emails sent through SFMC, without any auth. Assigned CVE-2026-22585, CVE-2026-22586, CVE-2026-22582, CVE-2026-22583, CVE-2026-2298. Read our writeup here: https://slcyber.io/research-center/ghosts-of-encryption-past-salesforce-exacttarget/

    Post summary

    Our team identified multiple CVEs in Salesforce Marketing Cloud that enable unauthenticated leakage of subscriber PII and emails, and they have published a writeup detailing the issue.

    025166387.0K
    10.3K followersView on X
  • CVEDatabase.com@cvedatabase
    Disclosure

    🔥 Salesforce Marketing Cloud has CVE-2026-22583 — critical command injection with a 9.8 CVSS score. Untested APIs make great targets. See vulnerability info & affected versions: 👉 https://cvedatabase.com/cve/CVE-2026-22583 #CloudSecurity #CVE

    Post summary

    The tweet announces a critical command injection vulnerability (CVE-2026-22583) in Salesforce Marketing Cloud, noting its high CVSS score and that untested APIs are potential targets.

    0000034
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsalesforcemarketing_cloud_engagement---

Explore more