PT-2026-4541 · Salesforce · Salesforce Marketing Cloud Engagement

S.Shah@Slcyber.Io

·

Published

2026-01-24

·

Updated

2026-05-05

·

CVE-2026-22583

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Salesforce Marketing Cloud Engagement versions prior to January 21st, 2026
Description Improper Neutralization of Argument Delimiters in a Command (Argument Injection) in the CloudPagesUrl module allows Web Services Protocol Manipulation. Argument Injection occurs when an application fails to properly sanitize user-supplied input used as a command-line argument, allowing an attacker to inject additional arguments to alter the command's behavior.
Recommendations Update to the version released on or after January 21st, 2026. Restrict the use of the CloudPagesUrl module as a temporary mitigation measure.

Fix

Argument Injection

Weakness Enumeration

Related Identifiers

CVE-2026-22583

Affected Products

Salesforce Marketing Cloud Engagement