CVE-2026-2298: Critical severity Salesforce Marketing Cloud Engagement vulnerability
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 30th, 2026.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2298?
CVE-2026-2298 is considered a medium severity vulnerability due to its potential for web services protocol manipulation.
How do I fix CVE-2026-2298?
To mitigate CVE-2026-2298, update your Salesforce Marketing Cloud Engagement to a version released after January 30, 2026.
What systems are affected by CVE-2026-2298?
CVE-2026-2298 affects all versions of Salesforce Marketing Cloud Engagement released before January 30, 2026.
What type of vulnerability is CVE-2026-2298?
CVE-2026-2298 is an argument injection vulnerability that allows improper neutralization of argument delimiters in commands.
Can CVE-2026-2298 lead to data breaches?
Yes, CVE-2026-2298 could potentially lead to unauthorized access and data breaches through web services protocol manipulation.