PT-2026-4541 · Salesforce · Salesforce Marketing Cloud Engagement
S.Shah@Slcyber.Io
·
Published
2026-01-24
·
Updated
2026-05-05
·
CVE-2026-22583
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Salesforce Marketing Cloud Engagement versions prior to January 21st, 2026
Description
Improper Neutralization of Argument Delimiters in a Command (Argument Injection) in the
CloudPagesUrl module allows Web Services Protocol Manipulation. Argument Injection occurs when an application fails to properly sanitize user-supplied input used as a command-line argument, allowing an attacker to inject additional arguments to alter the command's behavior.Recommendations
Update to the version released on or after January 21st, 2026.
Restrict the use of the
CloudPagesUrl module as a temporary mitigation measure.Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Salesforce Marketing Cloud Engagement