HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Guest User Misconfiguration Enables 17‑Month Data Harvest from Salesforce and ServiceNow Portals

An unauthenticated actor exploited over‑permissive guest‑user accounts in Salesforce Experience Cloud and ServiceNow portals, harvesting data from dozens of organizations over 17 months. The breach highlights the need for strict guest‑user permission controls and continuous audit evidence for SOC 2 readiness.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

Guest User Misconfiguration Enables 17‑Month Data Harvest from Salesforce and ServiceNow Portals

What Happened — Researchers tracking the “City‑Forum” campaign observed an unauthenticated actor repeatedly querying public Salesforce Experience Cloud and ServiceNow portals via their built‑in guest‑user accounts. Over 17 months the actor harvested records from dozens of organizations—including telecoms, banks, and public‑sector agencies—without exploiting a software flaw or stealing credentials.

Why It Matters for Compliance & Audit Readiness

  • The incident is a textbook example of an over‑permissive guest‑user configuration that bypasses the “need‑to‑know” principle, a control explicitly required by SOC 2 CC6.1 (Logical Access).
  • Continuous evidence of proper guest‑user permission reviews and automated control mapping can demonstrate due diligence to auditors and reduce the risk of undisclosed data exposure.
  • Verisq’s Control Mapping capability provides a real‑time view of guest‑user permissions against SOC 2 requirements and captures immutable audit evidence for the Trust Center.

Who Is Affected — Telecom operators, banks & financial‑services firms, enterprise‑software vendors, security‑and‑privacy solution providers, and public‑sector agencies that expose Salesforce Experience Cloud or ServiceNow knowledge‑base portals.

Recommended Actions

  • Conduct an immediate inventory of all guest‑user accounts in Salesforce and ServiceNow; verify that their permission sets align with the principle of least privilege.
  • Implement a continuous monitoring rule that flags any guest‑user permission changes and logs access attempts for audit review.
  • Map the guest‑user access control to SOC 2 CC6.1 and capture the evidence in a centralized Trust Center for future audits.

Technical Notes – The attacker leveraged no vulnerability; the vector was a misconfiguration of the default guest‑user profile, allowing enumeration of Aura framework objects in Salesforce and unrestricted reads in ServiceNow. No CVE is associated. Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/08/12/salesforce-servicenow-guest-user-exposure/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →