
Our team discovered a vulnerability in Salesforce Marketing Cloud that allowed us to leak PII of subscribers and emails sent through SFMC, without any auth. Assigned CVE-2026-22585, CVE-2026-22586, CVE-2026-22582, CVE-2026-22583, CVE-2026-2298. Read our writeup here: https://slcyber.io/research-center/ghosts-of-encryption-past-salesforce-exacttarget/
Post summary
Our team identified multiple CVEs in Salesforce Marketing Cloud that enable unauthenticated leakage of subscriber PII and emails, and they have published a writeup detailing the issue.

