CVE-2026-22583: Critical severity Salesforce Marketing Cloud Engagement vulnerability
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (CloudPagesUrl module) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22583?
CVE-2026-22583 has a critical severity level due to its potential for command injection.
How do I fix CVE-2026-22583?
To fix CVE-2026-22583, it is recommended to update Salesforce Marketing Cloud Engagement to a version released after January 21st, 2026.
What software is affected by CVE-2026-22583?
CVE-2026-22583 affects Salesforce Marketing Cloud Engagement versions before January 21st, 2026.
What type of vulnerability is CVE-2026-22583?
CVE-2026-22583 is classified as an Argument Injection vulnerability.
What are the risks associated with CVE-2026-22583?
The risks associated with CVE-2026-22583 include the ability for attackers to manipulate web services protocol interactions.