Home

Description

Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for Salesforce objects. This impacts OmniStudio: before Spring 2025

PUBLISHED Reserved 2025-04-16 | Published 2025-06-10 | Updated 2025-06-11 | Assigner Salesforce

Problem types

CWE-281 Improper Preservation of Permissions

Product status

Default status
unaffected

Any version before Spring 2025
affected

References

help.salesforce.com/s/articleView?id=004980323&type=1

cve.org (CVE-2025-43698)

nvd.nist.gov (CVE-2025-43698)

Download JSON