Drupal · Salesforce Suite · CVE-2026-13243
**Name of the Vulnerable Software and Affected Versions**
Drupal Salesforce Suite versions 0.0.0 through 5.1.3
**Description**
A Cross-Site Request Forgery (CSRF) issue exists where the software fails to properly validate the OAuth handshake during interactive authentication. This allows an attacker to hijack the authorization token and bind the site to an attacker-controlled Salesforce account. This issue requires the `salesforce oauth` submodule to be enabled and an active `salesforce oauth` authorization profile to be in use.
**Recommendations**
Update Drupal Salesforce Suite to version 6.0.x or later.
As a temporary mitigation, disable the `salesforce oauth` submodule or switch to the `salesforce jwt` authentication plugin.