CVE-2026-25650: MCP Salesforce Connector has arbitrary attribute access which leads to disclosure of Salesforce auth token
Impact Disclosure of Salesforce OAuth bearer tokens used by the MCP.
Patches fix applied in 0.1.10
Workarounds Rotate any Salesforce tokens/credentials used by MCP-Salesforce.
Other sources
MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.1.10, arbitrary attribute access leads to disclosure of Salesforce auth token. This vulnerability is fixed in 0.1.10.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25650?
CVE-2026-25650 has a moderate severity level due to its potential to disclose Salesforce OAuth bearer tokens.
How do I fix CVE-2026-25650?
To fix CVE-2026-25650, upgrade to version 0.1.10 of the MCP Salesforce Connector.
What is the impact of CVE-2026-25650?
The impact of CVE-2026-25650 is the potential disclosure of Salesforce authentication tokens used by the MCP.
Is there a workaround for CVE-2026-25650?
Yes, a workaround for CVE-2026-25650 is to rotate any Salesforce tokens and credentials used by the MCP Salesforce Connector.
Which versions are affected by CVE-2026-25650?
Versions of the MCP Salesforce Connector prior to 0.1.10 are affected by CVE-2026-25650.