Skip to content
Salesforce Experience Cloud misconfigurations exploited by ShinyHunters | brief

Salesforce Experience Cloud misconfigurations exploited by ShinyHunters | brief

Scworld March 10, 2026

Salesforce is alerting customers to a security issue affecting misconfigured Experience Cloud platforms, where hackers are exploiting guest accounts to access sensitive data. The ShinyHunters extortion gang claims responsibility for actively exploiting exposed instances to steal data, as reported by Bleeping Computer.

Attackers are leveraging a modified version of the open-source AuraInspector tool to target the /s/sfsites/aura API endpoint on misconfigured Salesforce Experience Cloud instances. This misconfiguration allows guest users unintended access to more data than they should have access to. Salesforce emphasizes that this is not a platform vulnerability but a result of customer-configured guest user settings granting excessive permissions.

The ShinyHunters gang claims to have compromised between 300 and 400 organizations, many in the cybersecurity sector, by exploiting these access control weaknesses. They reportedly found ways to bypass data query limitations, accelerating data theft.

Source: Bleeping Computer

Extracted Entities

Attack Types (1)

Tools (1)