Argument Injection Vulnerability in Salesforce Marketing Cloud Engagement
CVE-2026-22583
9.8CRITICAL
What is CVE-2026-22583?
A vulnerability in Salesforce Marketing Cloud Engagement's CloudPagesUrl module allows for improper neutralization of argument delimiters, potentially enabling web services protocol manipulation. This could expose systems to various risks, depending on how the affected product handles inputs. Users and organizations should take precautions to secure their instances before the specified date to prevent exploitation of this issue.
Affected Version(s)
Marketing Cloud Engagement 0
