Description
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.
Published: 2026-01-24
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Web Services Protocol Manipulation
Action: Apply Patch
AI Analysis

Impact

Salesforce Marketing Cloud Engagement employs a broken or risky cryptographic algorithm in several web‑page and data‑synchronization modules—CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, and View As Webpage. This weakness, classified as CWE‑327, undermines the integrity of the Web Services Protocol and permits an attacker to manipulate protocol traffic. The vulnerability does not, on its own, specify that an attacker can exfiltrate data or execute code; it only indicates that crafted requests could alter or inject protocol messages.

Affected Systems

Every instance of Marketing Cloud Engagement running a version released before January 21 2026 is affected. The vulnerability spans all modules that expose web services endpoints within the platform, so any customer who has not yet upgraded beyond the specified release date remains vulnerable.

Risk and Exploitability

The CVSS score of 9.8 signals a critical threat, yet the EPSS score of less than 1% suggests a low probability of exploitation at this time. The flaw is not listed in the CISA KEV catalog. An attacker presumed to have access to the exposed web services could send specially crafted requests over HTTP/HTTPS to the vulnerable modules, manipulating protocol messages as the broken cryptographic algorithm fails to verify integrity. The risk rises for publicly exposed instances or environments lacking strict input validation at the web‑services layer.

Generated by OpenCVE AI on April 18, 2026 at 15:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the Salesforce Marketing Cloud Engagement release dated January 21 2026 or later, which removes the risky cryptographic algorithm and patches the protocol manipulation flaw.
  • If an upgrade cannot be performed immediately, temporarily block or restrict access to the affected modules—CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center and View As Webpage—at the application or network level.
  • Enable detailed logging and continuous monitoring of Web Services API traffic, configuring alerts for abnormal or unexpected requests to detect attempted protocol manipulation.

Generated by OpenCVE AI on April 18, 2026 at 15:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
Title Risky Cryptographic Algorithm Enables Web Services Protocol Manipulation in Salesforce Marketing Cloud Engagement

Thu, 12 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:salesforce:marketing_cloud_engagement:*:*:*:*:*:*:*:*

Mon, 26 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Salesforce
Salesforce marketing Cloud Engagement
Vendors & Products Salesforce
Salesforce marketing Cloud Engagement

Sat, 24 Jan 2026 00:45:00 +0000

Type Values Removed Values Added
Description Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.
Weaknesses CWE-327
References

Subscriptions

Salesforce Marketing Cloud Engagement
cve-icon MITRE

Status: PUBLISHED

Assigner: Salesforce

Published:

Updated: 2026-04-29T19:22:03.124Z

Reserved: 2026-01-07T19:03:25.721Z

Link: CVE-2026-22585

cve-icon Vulnrichment

Updated: 2026-01-26T16:27:18.689Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-24T01:15:50.167

Modified: 2026-02-12T16:08:29.020

Link: CVE-2026-22585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T15:15:03Z

Weaknesses