Threat actors using modified AuraInspector to mass-scan Salesforce Experience Cloud sites

by

In a blog post by Salesforce, the company warned that threat actors are mass-scanning public Experience Cloud sites with a modified AuraInspector to exploit overly permissive guest user configurations and extract data.

KEY FACTS

  • Tool Modified AuraInspector used to identify and extract data
  • Target Public Experience Cloud sites with guest user misconfigurations
  • Impact Unauthenticated queries to Salesforce CRM objects possible
  • Mitigation Review guest user settings and restrict external access

The custom tool goes beyond the original AuraInspector functionality to perform mass scanning and to extract data from sites that expose API endpoints for the Aura framework.

Public Experience Cloud sites use a dedicated guest user profile to serve landing pages and knowledge content. If that profile has excessive permissions, unauthenticated users can query CRM objects without logging in.

Successful exploitation requires two customer conditions: use of the guest user profile and failure to follow recommended configuration guidance. No inherent platform vulnerability has been identified.

Customers should review guest user settings, set Default External Access for all objects to Private, disable guest access to public APIs, restrict visibility that permits internal user enumeration, disable self-registration when not needed and monitor logs for unusual queries.

WHY IT MATTERS

Misconfigured guest profiles can let attackers harvest personal and contact data that can be used for follow-on social engineering and voice phishing campaigns. Customers must check access controls to limit exposure.