Improper Preservation of Permissions in Salesforce OmniStudio FlexCards
CVE-2025-43698

Currently unrated

Key Information:

Vendor

Salesforce

Vendor
CVE Published:
10 June 2025

Badges

👾 Exploit Exists📰 News Worthy

What is CVE-2025-43698?

A vulnerability exists in Salesforce OmniStudio, specifically within FlexCards, that enables the bypass of field-level security controls for Salesforce objects. This leads to unauthorized access to sensitive data and user permissions within the application, posing a significant risk to data integrity and confidentiality.

Affected Version(s)

OmniStudio 0

News Articles

Researchers Uncover 20+ Configuration Risks, Including Five CVEs, in Salesforce Industry Cloud

Salesforce Industry Cloud has 20+ config risks exposing sensitive data; customers must fix most issues to avoid compliance and security breaches.

21 hours ago

References

Timeline

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-43698 : Improper Preservation of Permissions in Salesforce OmniStudio FlexCards