
Our team discovered a vulnerability in Salesforce Marketing Cloud that allowed us to leak PII of subscribers and emails sent through SFMC, without any auth. Assigned CVE-2026-22585, CVE-2026-22586, CVE-2026-22582, CVE-2026-22583, CVE-2026-2298. Read our writeup here: https://slcyber.io/research-center/ghosts-of-encryption-past-salesforce-exacttarget/
Post summary
The post announces the discovery and public disclosure of multiple CVEs in Salesforce Marketing Cloud that enable unauthenticated leakage of subscriber PII and email data, accompanied by a link to a detailed writeup.


