PT-2026-52176 · Drupal+3 · Salesforce Suite+2

·

CVE-2026-13243

·

Published

2026-06-24

·

Updated

2026-08-06

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal Salesforce Suite versions 0.0.0 through 5.1.3
Description A Cross-Site Request Forgery (CSRF) issue exists where the software fails to properly validate the OAuth handshake during interactive authentication. This allows an attacker to hijack the authorization token and bind the site to an attacker-controlled Salesforce account. This issue requires the salesforce oauth submodule to be enabled and an active salesforce oauth authorization profile to be in use.
Recommendations Update Drupal Salesforce Suite to version 6.0.x or later. As a temporary mitigation, disable the salesforce oauth submodule or switch to the salesforce jwt authentication plugin.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13243
DRUPAL-CONTRIB-2026-063

Affected Products

Salesforce Suite
Drupal/Salesforce
Salesforce