Overly Permissive Experience Cloud Guest Settings Expose Data

Actors are exploiting overly permissive Salesforce Experience Cloud guest-user settings to access and steal customer data. Salesforce says this stems from customer misconfiguration, not a platform flaw, and affects public Experience Cloud sites with exposed guest permissions. Review and tighten

Part of the PlainSec briefing for 2026-03-15

Sources