Executive brief
A security vulnerability exists in several modules of Salesforce Marketing Cloud Engagement, including CloudPages and the Subscription Center. This flaw stems from the use of a fixed, predictable security key, which could allow an unauthorized person to manipulate web service communications. If exploited, this could lead to unauthorized access to customer profile data or the ability to modify subscription preferences and marketing content.
Technical details
A hard-coded cryptographic key vulnerability (CWE-321) exists within multiple modules of Salesforce Marketing Cloud Engagement, specifically CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, and View As Webpage. The use of a static key allows for Web Services Protocol Manipulation, where an unauthenticated remote attacker can potentially decrypt, forge, or modify sensitive service requests. This is a network-based attack requiring no user interaction or special privileges. Salesforce addressed this issue in an update released on January 21, 2026.
Affected products
- Salesforce Marketing Cloud Engagement Before January 21, 2026
Timeline
- 2026-01-21: patched: Issue addressed in Marketing Cloud Engagement update
- 2026-01-23: advisory: Initial advisory published by Salesforce
- 2026-01-24: disclosed: CVE published to NVD