CVE-2026-22582: Critical severity Salesforce Marketing Cloud Engagement vulnerability
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (MicrositeUrl module) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22582?
CVE-2026-22582 is classified as a critical vulnerability due to its potential for web services protocol manipulation.
How do I fix CVE-2026-22582?
To address CVE-2026-22582, ensure that your Salesforce Marketing Cloud Engagement system is updated to a version released after January 21st, 2026.
What impact does CVE-2026-22582 have on my system?
CVE-2026-22582 can allow attackers to manipulate web services protocols, leading to unauthorized access or data leakage.
Which versions of Salesforce Marketing Cloud Engagement are affected by CVE-2026-22582?
CVE-2026-22582 affects all versions of Salesforce Marketing Cloud Engagement prior to January 21st, 2026.
Is there a workaround for CVE-2026-22582?
Currently, the recommended solution for CVE-2026-22582 is to upgrade to the fixed version after the specified date.