PT-2025-22118 · Salesforce · Omnis Studio

Published

2025-05-20

·

Updated

2025-06-10

·

CVE-2025-43698

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Salesforce OmniStudio versions prior to Spring 2025
Description The issue is related to an Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards), which allows the bypass of field level security controls for Salesforce objects.
Recommendations For Salesforce OmniStudio versions prior to Spring 2025, update to a version released after Spring 2025 to resolve the issue. As a temporary workaround, consider restricting access to sensitive Salesforce objects to minimize the risk of exploitation.

Fix

Improper Preservation of Permissions

Weakness Enumeration

Related Identifiers

CVE-2025-43698

Affected Products

Omnis Studio