CVE-2026-25650: MCP Salesforce Connector leaks Salesforce auth token
A vulnerability in the MCP Salesforce Connector, a Model Context Protocol server for Salesforce integration, allowed arbitrary attribute access that could disclose the Salesforce authentication token. The issue affects versions prior to 0.1.10 and is fixed in 0.1.10.
Disclosed 6 February 2026 · Record updated 13 September 2026
Impact
Arbitrary attribute access in the MCP server could expose Salesforce authentication tokens to attackers.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-25650
