CVE-2026-22586 PUBLISHED

Assigner: Salesforce
Reserved: 07.01.2026 Published: 24.01.2026 Updated: 24.01.2026

Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.

Product Status

Vendor Salesforce
Product Marketing Cloud Engagement
Versions Default: unaffected
  • affected from 0 to January 21, 2026 (excl.)

References

Problem Types

  • CWE-321 Hard-coded Cryptographic Key CWE

Impacts

  • CAPEC-278 Web Services Protocol Manipulation