Campaign exploits over-permissive Salesforce Experience Cloud guest accounts
Salesforce reports an ongoing campaign targeting Experience Cloud guest accounts that have been granted excessive permissions. The threat actor uses a modified version of the legitimate open-source tool Aura Inspector to exfiltrate data through these accounts. Salesforce stresses that this is not a system vulnerability but poor configuration granting the guest user too much access. The company has published a list of recommended mitigations.
What this means for your business
No patch helps here. Responsibility rests entirely with whoever configured the solution, and that is precisely the part of shared cloud responsibility that tends to go unattended. Customer portals and partner sites are often built under time pressure, with permissions set wide to make something work. If customer data is extracted this way, it is a personal data breach, without anyone having broken in anywhere.
Berigo recommends
- Review which objects and fields the guest user profile can actually read, and remove everything not required for the portal to function.
- Follow the mitigation list from Salesforce and document the review as a control you can point to.
- Enable and review logging of data extraction from portal surfaces so abnormal volumes become visible.
- Schedule recurring permission reviews for SaaS solutions with external users, not just at initial setup.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch