PT-2026-4540 · Salesforce · Salesforce Marketing Cloud Engagement

S.Shah@Slcyber.Io

·

Published

2026-01-24

·

Updated

2026-05-05

·

CVE-2026-22582

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Salesforce Marketing Cloud Engagement versions prior to January 21st, 2026
Description Improper Neutralization of Argument Delimiters in a Command, also known as Argument Injection, in the MicrositeUrl module allows Web Services Protocol Manipulation. Argument Injection occurs when an application fails to properly sanitize user-supplied input used as a command-line argument, allowing an attacker to inject additional arguments to alter the command's behavior.
Recommendations Update Salesforce Marketing Cloud Engagement to a version released on or after January 21st, 2026. As a temporary workaround, restrict the use of the MicrositeUrl module to minimize the risk of exploitation.

Fix

Argument Injection

Weakness Enumeration

Related Identifiers

CVE-2026-22582

Affected Products

Salesforce Marketing Cloud Engagement