CVE-2026-2298
CRITICALSalesforce Marketing Cloud Engagement - Command Injection
Title source: llmDescription
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 30th, 2026.
Scores
CVSS v3
9.4
EPSS
0.0007
EPSS Percentile
20.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-88
Status
published
Products (1)
Salesforce/Marketing Cloud Engagement
< January 30th, 2026
Published
Mar 23, 2026
Tracked Since
Mar 24, 2026